Simple Translate
ibplnjkanclpjokhdolnendpplpjiace
Risk Score
4.18
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — does not scope to this extension at all (+10.0 privacy).
- Content script runs on <all_urls>; 3x innerHTML sinks with no CSP amplify DOM-XSS risk.
- Free-webmail developer (gmail) with no verified business domain raises accountability gap.
- uninstall_url_hijack flagged true — may redirect users on uninstall.
- 10 distinct JS external hosts including translate APIs, fb.me, example.com — broader than necessary.
Evidence
- privacy_policy_generic store Policy URL points to Google account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5D).
- content_scripts_all_urls manifest content_scripts_matches includes <all_urls>, http://*/* and https://*/* — broad host injection.
- dom_sink_innerhtml_no_csp crx 3 innerHTML findings across popup, options, content scripts; csp_present=false triggers FIX B +2.0 code quality.
- uninstall_url_hijack crx uninstall_url_hijack=true; target null but Webstore rule applies +3.0.
- free_webmail_developer store Developer email is gmail; no verified publisher badge; +1.5 reputation per free-webmail rule.
- is_featured_by_google store Extension carries Featured badge; -2.0 reputation discount applied.
- js_external_hosts_count crx 10 distinct external hosts including fb.me, example.com, developer.mozilla.org beyond core translate APIs.
- no_cve_findings crx cve_findings_raw empty; CVE pillar = 0.0.
Permissions Breakdown
- storage low Stores user preferences locally; no remote exfil risk alone.
- contextMenus low Adds right-click translate option; limited capability.
- content_scripts <all_urls> high Injects JS into every page; broadens DOM-XSS attack surface significantly.
Pillar Scores
Permissions3.50
Reputation6.00
Network2.00
Webstore3.50
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Scoring History
| sssiedn66303e6adp727562726963xsx | 4.14 | Medium | review | 2026-08-30 |
| sssieddrubricxsx | 4.22 | Medium | review | 2026-08-15 |
| v3.6 | 4.18 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:41
Listing SHA
a64b42e621b1…
Force block
— not fired
Score recovered
no
Elapsed
24.6s