Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Language Reactor

hoombieeljmmljlkjmnheibnpciblicm
Risk Score
2.82
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category TranslationTool
Installs 2,000,000
Rating 4.2
Last updated 2026-03-07 (3 months ago)
Manifest version MV3
CSP present ✅ yes
Developer languagelearningextension@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Developer uses free Gmail address (languagelearningextension@gmail.com) with no verified business identity.
  • Privacy policy does not disclose data retention period; third-party sharing is mentioned but unscoped.
  • new Function() constructor present in background.min.js — low-risk pattern but noteworthy in minified code.
  • Content scripts run on all Amazon TLDs, YouTube, and Netflix — broad reach on high-value commerce/media sites.
  • Privacy policy hosted on legacy domain (languagelearningwithnetflix.com) differing from active brand domain.

Evidence

  • free_webmail_developer store Developer email is languagelearningextension@gmail.com — no verified business domain.
  • content_scripts_broad_reach manifest Content scripts declared on 20 Amazon TLDs + youtube.com + netflix.com; justified for language-learning.
  • privacy_policy_gaps crx Policy fetched; scope_extension=true, data_collection=false, but retention=false and third_party_sharing=true.
  • function_constructor_in_background crx new Function('return this') found in background.min.js — common polyfill pattern, low exfil risk.
  • no_cve_findings crx jquery 3.6.0 bundled; no CVEs reported. No bad-host or affiliate hits in threat_intel.
  • recently_updated store Last updated March 7, 2026 (3 months ago); maintenance risk is minimal.
  • csp_present_mv3 manifest MV3 with explicit CSP; script-src 'self' only, no unsafe-eval or remote CDN script sources.
  • no_operator_siblings_no_bad_hosts api operator_cluster sibling_count=0; bad_host_hits=[], affiliate_hits=[], monetization_hits=[] confirmed clean.

Permissions Breakdown

  • storage low Saves user preferences/vocabulary locally; standard for this category.
  • contextMenus low Adds right-click lookup menu; expected for language tools.
  • activeTab low Scoped to user-activated tab only; low blast radius.
  • scripting medium Allows runtime script injection into pages; medium risk but consistent with stated function.
  • host: https://i.ytimg.com/* low YouTube thumbnail CDN only; very narrow scope.
  • content_scripts: amazon/youtube/netflix/languagereactor medium Runs on major streaming/retail sites; justified by language-learning function.

Pillar Scores

Permissions2.30
Reputation6.50
Network2.00
Webstore2.00
Maintenance0.00
Privacy2.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:41
Listing SHA 174cbfcdceb5…
Force block — not fired
Score recovered no
Elapsed 24.5s