Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Translate to Many Languages at Once

jhjpmdlflhfmhocmleiclpiiajkdmhfh
Risk Score
4.04
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category TranslationTool
Installs 147
Rating
Last updated 2026-08-19 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@peakproductivity.online
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack to peakproductivity.online — exfils uninstall events to 3rd-party server (+3.0 webstore).
  • Install URL hijack present — onInstalled callback opens external URL.
  • 12 external JS hosts contacted including sendsimple.site, two translatetomanylanguages.* domains alongside AI APIs — opaque data routing.
  • Privacy policy admits third-party data sharing with no retention disclosure; scoped but inadequate.
  • Very low install base (147) for an AI translation tool routing data to multiple AI provider APIs and Stripe.

Evidence

  • uninstall_url_hijack manifest chrome.runtime.setUninstallURL targets https://peakproductivity.online/translate-many/uninstall/ — 3rd-party beacon on removal.
  • install_url_hijack manifest onInstalled redirect present (target null in listing but flag set true).
  • js_external_hosts crx 12 external hosts: AI APIs (openai,anthropic,deepl), Stripe, sendsimple.site, 2 translatetomanylanguages.* domains, translation.googleapis.com.
  • privacy_policy_third_party_sharing api Policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
  • dom_sink_innerhtml_userctrl crx results/results.js assigns innerHTML from variable — potential DOM-XSS sink.
  • unverified_publisher_dotOnline_domain store No verified publisher badge; developer domain peakproductivity.online (.online TLD, elevated-risk).
  • geo_diversity api JS hosts span 4 countries (CA, DE, KR, US) — broad network surface for a translation tool.
  • no_ratings store 147 installs, 0 ratings — no community trust signal whatsoever.

Permissions Breakdown

  • storage low Standard local state persistence; no cross-site risk.
  • downloads medium Can write files to disk; potential for file-based abuse.
  • contextMenus low Adds right-click items; low capability on its own.

Pillar Scores

Permissions1.60
Reputation6.00
Network1.50
Webstore8.00
Maintenance0.00
Privacy2.00
Code Quality0.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 15:52
Listing SHA 225111530167…
Force block — not fired
Score recovered no
Elapsed