Google Translate in Side Panel
lopnbnfpjmgpbppclhclehhgafnifija
Risk Score
2.82
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Brand impersonation: title says 'Google Translate' but developer is not Google (confirmed_owner=false).
- Content scripts run on ALL http/https pages giving broad passive access to page content.
- Developer domain (zenttranslate.com) differs from privacy policy domain (ag-translate.com) — identity mismatch.
- No developer name listed; extension contacts 3 distinct search engines (Google, Bing, Baidu) raising multi-provider concern.
- Geo-diverse JS hosts across 4 countries (AR, CA, HK, US) for a translation tool warrants monitoring.
Evidence
- brand_impersonation store Title contains 'Google Translate'; brand_mention.is_impersonation=true, confirmed_owner=false, developer is zenttranslate.com.
- verified_publisher+featured store Extension has verified_publisher=true and is_featured_by_google=true, reducing reputation risk.
- broad_content_scripts manifest content_scripts_matches includes http://*/* and https://*/* — runs on every page.
- privacy_policy_domain_mismatch store Developer email @zenttranslate.com; privacy policy at ag-translate.com — different domains.
- privacy_policy_classification crx Policy fetched, scoped, documents collection, retention, and third-party sharing — adequate.
- search_engine_count_3 crx threat_intel shows 3 search engines contacted (Google, Bing, Baidu) — consistent with multi-engine translation.
- no_code_findings crx code_findings_raw empty; obfuscation_score=0.0; 17 JS files scanned cleanly.
- geo_diversity crx JS hosts span 4 countries (AR, CA, HK, US); category TranslationTool partially justifies global reach.
Permissions Breakdown
- storage low Local state persistence only.
- sidePanel low UI surface, no data access.
- contextMenus low Adds right-click menu items.
- declarativeNetRequest medium Can modify/block network requests declaratively.
- scripting medium Can inject scripts; mitigated by activeTab + host scope.
- activeTab medium Transient page access on user interaction.
- tts low Text-to-speech output only.
- host:translate.googleapis.com low Google Translate API — matches stated function.
- host:translate.google.com low Google Translate — matches stated function.
- host:translate-pa.googleapis.com low Google Translate private API — matches function.
- host:edge.microsoft.com low Microsoft Edge services for Bing Translate support.
- host:api-edge.cognitive.microsofttranslator.com low Microsoft Translator API — matches function.
- host:*.bing.com low Bing Translate support — matches function.
- host:fanyi.baidu.com low Baidu Translate — matches function.
- host:www.deepl.com low DeepL Translate — matches function.
- host:www.zenttranslate.com medium Developer's own domain — potential telemetry endpoint.
- host:agtranslate.com medium Second developer domain; privacy policy domain mismatch.
- host:dict.youdao.com low Youdao dictionary — plausible translation support.
- content_scripts:http://*/*,https://*/* high Broad content script injection on all sites — highest capability.
Pillar Scores
Permissions4.50
Reputation4.00
Network3.00
Webstore4.00
Maintenance0.00
Privacy0.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 07:59
Listing SHA
4961bc5db5be…
Force block
— not fired
Score recovered
no
Elapsed
—