Translator
icchadngbpkcegnabnabhkjkfkfflmpj
Risk Score
4.73
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Gmail developer email with 3rd-party privacy policy domain (app-loady.com) — no verified business identity.
- install_url_hijack=true: extension opens 3rd-party URL on install, classic monetization/adware pattern.
- scripting + <all_urls> content_scripts allow code injection on every site the user visits.
- Privacy policy admits data collection and third-party sharing but no retention period disclosed.
- 18 months since last update; extension at maintenance boundary with broad host access.
Evidence
- install_url_hijack manifest install_url_hijack=true; extension redirects user on install to 3rd-party URL — monetization/adware indicator.
- developer_identity store Dev email henrikdoiakc@gmail.com (free webmail); privacy policy on app-loady.com — unrelated domain, no verified business.
- broad_host_access manifest <all_urls> host_permission + content_scripts on <all_urls> + scripting permission — full-page access on all sites.
- privacy_policy_classification api Policy fetched: scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
- js_external_hosts crx 8 external JS hosts including getbootstrap.com, jquery.org, popper.js.org — CDN references in extension code.
- no_csp manifest content_security_policy is null; csp_present=false on MV3 extension with external host references.
- maintenance store Last updated February 23, 2025; 18 months since update — at 6-month maintenance penalty boundary.
- obfuscation_code_quality crx obfuscation_score=0.0; code_findings_raw empty; 18 JS files scanned — no malicious code detected.
Permissions Breakdown
- contextMenus low Adds right-click menu items; low standalone risk.
- activeTab low Scoped to current tab on user action; limited exposure.
- storage low Stores extension settings locally.
- tabs medium Can read tab URLs and metadata across sessions.
- system.display low Reads display configuration; unusual for a translator but low risk.
- declarativeNetRequest medium Can block/redirect network requests; potential for content manipulation.
- scripting medium Can inject scripts into pages; paired with <all_urls> increases reach.
- <all_urls> (host_permission) high Broad host access across all sites; amplifies scripting and declarativeNetRequest risk.
Pillar Scores
Permissions5.50
Reputation6.50
Network4.00
Webstore4.00
Maintenance6.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 07:52
Listing SHA
ffba03cad81b…
Force block
— not fired
Score recovered
no
Elapsed
—