Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Translate - Translator, Dictionary, TTS

mnlohknjofogcljbcknkakphddjpijak
Risk Score
3.71
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category TranslationTool
Installs 100,000
Rating 4.5
Last updated 2026-04-20 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer almzwhitey083@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but does not scope to this extension and admits data collection — worst-case generic policy with silent 3rd-party clause.
  • Developer uses free Gmail address with no dev name; accountability gap despite verified publisher badge.
  • jquery@3.4.1 bundled with two medium XSS CVEs (CVE-2020-11022, CVE-2020-11023); no CSP amplifies risk.
  • Content scripts inject on all http/https pages with <all_urls> host permission — broad page-content access.
  • 10 external JS hosts contacted (lingvanex, backenster, u-language, jqueryui, Firebase/Google consoles) with no CSP.

Evidence

  • verified_publisher + featured store Extension carries verified publisher and featured badges; reputation discounts applied but capped per v3.5-E due to privacy concern.
  • gmail_dev_no_name store developer_email=almzwhitey083@gmail.com; developer_name empty. Free-webmail identity, no business attribution.
  • jquery_cve crx jquery@3.4.1 bundled; CVE-2020-11022 and CVE-2020-11023 (XSS, moderate). fixed_in=3.5.0, not patched.
  • no_csp crx content_security_policy is null (MV3 default strict but no explicit CSP; jquery CVEs gain dom-sink amplifier).
  • privacy_policy_scope_fail api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=false, retention=false. Generic non-scoped policy.
  • 10_external_hosts crx js_external_hosts includes backenster.com, lingvanex.com, u-language.com, jqueryui.com, Firebase console endpoints — >3 distinct domains.
  • install_url_hijack crx install_url_hijack=true with null target; onInstalled fires but destination unresolved — moderate concern.
  • content_scripts_all_urls manifest content_scripts_matches=[http://*/*, https://*/*] with <all_urls> host_permissions — injects on every page.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2020-11022 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • contextMenus low Standard right-click menu integration; low capability.
  • storage low Local preference/settings persistence only.
  • tabs medium Can read tab URLs and titles; privacy-relevant but common for translation tools.
  • <all_urls> (host_permissions) high Broad host access across all sites; content scripts inject on all http/https. Justified for translation but high surface.

Pillar Scores

Permissions3.80
Reputation4.50
Network3.50
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure3.00

Scoring History

v3.6 3.71 Low review 2026-06-16
v3.4-rev 4.22 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:57
Listing SHA 08410914d456…
Force block — not fired
Score recovered no
Elapsed 25.8s