AI Language Learning, Translation, Word Marking - NeonLingo
ifhljpgdgoimmfacomakolapgnamfkbd
Risk Score
2.47
Risk Level:
Low
Recommendation:
✅ ALLOW
Top Risks
- Content script on <all_urls> gives page-content access on every site despite low declared permissions.
- Gmail developer with no developer name reduces accountability; free-webmail identity.
- Privacy policy collects data and shares with third parties without disclosing retention period.
- No CSP declared (MV3 default applies but adds no extension-specific constraint); 6 external JS hosts contacted.
- AI/translation extension processes page content on all sites — exfil risk if ever compromised or sold.
Evidence
- content_scripts_broad manifest content_scripts matches <all_urls>; injects into every page the user visits.
- free_webmail_dev store Developer email aokodesuka@gmail.com; no developer name listed; reduces accountability.
- privacy_policy_third_party_sharing api Policy fetched: scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
- verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; reputation partially mitigated.
- js_external_hosts crx 6 external hosts in JS: developer.mozilla.org, github.com, motion.dev, react.dev, www.neonlingo.com, wxt.dev.
- no_cve_no_obfuscation crx cve_findings_raw empty, obfuscation_score=0.0, code_findings_raw empty; code quality clean.
- no_bad_hosts_no_affiliate api threat_intel shows no bad_host_hits, no affiliate_hits, no monetization_hits.
- recently_updated store Last updated June 10, 2026; months_since_update=0; maintenance risk minimal.
Permissions Breakdown
- storage low Stores user preferences and vocabulary locally; expected for language learning tool.
- activeTab low Accesses current tab on user action only; limited scope.
- background low Keeps service worker alive for alarms/sync; standard MV3 pattern.
- alarms low Schedules reminders for language learning; low risk.
- unlimitedStorage low Stores vocabulary datasets; expected for language app.
- tabs medium Can read tab URLs/titles across all open tabs; broader than activeTab alone.
- content_scripts:<all_urls> medium Injects scripts on every page for word marking; justified for translation tool but broad reach.
Pillar Scores
Permissions3.50
Reputation4.50
Network1.50
Webstore2.50
Maintenance0.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:42
Listing SHA
168d81f35088…
Force block
— not fired
Score recovered
no
Elapsed
22.7s