Translate - Translator, Dictionary, TTS
mnlohknjofogcljbcknkakphddjpijak
Risk Score
3.71
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy fetched but does not scope to this extension and admits data collection — worst-case generic policy with silent 3rd-party clause.
- Developer uses free Gmail address with no dev name; accountability gap despite verified publisher badge.
- jquery@3.4.1 bundled with two medium XSS CVEs (CVE-2020-11022, CVE-2020-11023); no CSP amplifies risk.
- Content scripts inject on all http/https pages with <all_urls> host permission — broad page-content access.
- 10 external JS hosts contacted (lingvanex, backenster, u-language, jqueryui, Firebase/Google consoles) with no CSP.
Evidence
- verified_publisher + featured store Extension carries verified publisher and featured badges; reputation discounts applied but capped per v3.5-E due to privacy concern.
- gmail_dev_no_name store developer_email=almzwhitey083@gmail.com; developer_name empty. Free-webmail identity, no business attribution.
- jquery_cve crx jquery@3.4.1 bundled; CVE-2020-11022 and CVE-2020-11023 (XSS, moderate). fixed_in=3.5.0, not patched.
- no_csp crx content_security_policy is null (MV3 default strict but no explicit CSP; jquery CVEs gain dom-sink amplifier).
- privacy_policy_scope_fail api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=false, retention=false. Generic non-scoped policy.
- 10_external_hosts crx js_external_hosts includes backenster.com, lingvanex.com, u-language.com, jqueryui.com, Firebase console endpoints — >3 distinct domains.
- install_url_hijack crx install_url_hijack=true with null target; onInstalled fires but destination unresolved — moderate concern.
- content_scripts_all_urls manifest content_scripts_matches=[http://*/*, https://*/*] with <all_urls> host_permissions — injects on every page.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2020-11022 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- contextMenus low Standard right-click menu integration; low capability.
- storage low Local preference/settings persistence only.
- tabs medium Can read tab URLs and titles; privacy-relevant but common for translation tools.
- <all_urls> (host_permissions) high Broad host access across all sites; content scripts inject on all http/https. Justified for translation but high surface.
Pillar Scores
Permissions3.80
Reputation4.50
Network3.50
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure3.00
Scoring History
| v3.6 | 3.71 | Low | review | 2026-06-16 |
| v3.4-rev | 4.22 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:57
Listing SHA
08410914d456…
Force block
— not fired
Score recovered
no
Elapsed
25.8s