Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Simple Translate

ibplnjkanclpjokhdolnendpplpjiace
Risk Score
4.18
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category TranslationTool
Installs 200,000
Rating 4.5
Last updated 2026-08-25
Manifest version MV3
CSP present ❌ no
Developer sienori.firefox+c@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — does not scope to this extension at all (+10.0 privacy).
  • Content script runs on <all_urls>; 3x innerHTML sinks with no CSP amplify DOM-XSS risk.
  • Free-webmail developer (gmail) with no verified business domain raises accountability gap.
  • uninstall_url_hijack flagged true — may redirect users on uninstall.
  • 10 distinct JS external hosts including translate APIs, fb.me, example.com — broader than necessary.

Evidence

  • privacy_policy_generic store Policy URL points to Google account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5D).
  • content_scripts_all_urls manifest content_scripts_matches includes <all_urls>, http://*/* and https://*/* — broad host injection.
  • dom_sink_innerhtml_no_csp crx 3 innerHTML findings across popup, options, content scripts; csp_present=false triggers FIX B +2.0 code quality.
  • uninstall_url_hijack crx uninstall_url_hijack=true; target null but Webstore rule applies +3.0.
  • free_webmail_developer store Developer email is gmail; no verified publisher badge; +1.5 reputation per free-webmail rule.
  • is_featured_by_google store Extension carries Featured badge; -2.0 reputation discount applied.
  • js_external_hosts_count crx 10 distinct external hosts including fb.me, example.com, developer.mozilla.org beyond core translate APIs.
  • no_cve_findings crx cve_findings_raw empty; CVE pillar = 0.0.

Permissions Breakdown

  • storage low Stores user preferences locally; no remote exfil risk alone.
  • contextMenus low Adds right-click translate option; limited capability.
  • content_scripts <all_urls> high Injects JS into every page; broadens DOM-XSS attack surface significantly.

Pillar Scores

Permissions3.50
Reputation6.00
Network2.00
Webstore3.50
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Scoring History

sssiedn66303e6adp727562726963xsx 4.14 Medium review 2026-08-30
sssieddrubricxsx 4.22 Medium review 2026-08-15
v3.6 4.18 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:41
Listing SHA a64b42e621b1…
Force block — not fired
Score recovered no
Elapsed 24.6s