Aub's Omnipotent Image Translator
moooomjnjdmhilaabhdkappiecdggnje
Risk Score
6.38
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Privacy policy is Google's own policy (not scoped to this extension), admits data collection and 3rd-party sharing — worst-case privacy rating.
- Free-webmail developer (jackthebaker123@gmail.com) with no business domain; numbered-alias style email raises credibility concerns.
- Uninstall URL hijack enabled; extension registers a custom uninstall hook indicating tracking/redirect behavior.
- 12 external JS hosts including multiple Alibaba/Aliyun telemetry endpoints and livepolls.app — high geo-diversity (CN/SG/CA/US) for a translation tool.
- small_install_high_perm anomaly: 671 installs with broad host+scripting permissions creates tail-attack surface risk.
Evidence
- free_webmail_dev store Developer email jackthebaker123@gmail.com — free webmail, no business domain, no verified publisher.
- privacy_policy_generic_google store Privacy URL points to Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- uninstall_url_hijack crx uninstall_url_hijack=true; extension registers uninstall URL hook suggesting user tracking post-removal.
- external_hosts_aliyun_telemetry crx arms-retcode.aliyuncs.com, arms-retcode-sg.aliyuncs.com, arms-retcode-daily.alibaba.net — Alibaba telemetry/monitoring endpoints.
- geo_diversity_4_countries crx JS external hosts span CA, CN, SG, US — 4 countries for a translation extension triggers geo-diversity signal.
- broad_host_plus_scripting manifest scripting + http://*/* + https://*/* + content_scripts <all_urls>: can read/modify any page.
- install_perm_anomaly api 671 installs with high-tier permissions (small_install_high_perm=true, tail_attack_surface=true).
- stale_20_months store Last updated December 2024; 20 months since update — falls in 6-month+ maintenance penalty band.
Permissions Breakdown
- sidePanel low UI panel only, low intrinsic risk.
- identity medium Can obtain Google OAuth tokens; identity data exposure risk.
- identity.email medium Explicitly reads user's Google email; PII exposure.
- storage low Local extension storage only.
- contextMenus low Adds right-click menu items; minimal risk.
- scripting high Can inject JS into any page; paired with broad host access.
- activeTab low Limited to user-activated tab; low standalone risk.
- http://*/* high Broad host permission over all HTTP sites.
- https://*/* high Broad host permission over all HTTPS sites.
- <all_urls> (content_scripts) high Content scripts injected on every page visited.
Pillar Scores
Permissions7.00
Reputation7.50
Network6.00
Webstore7.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 09:57
Listing SHA
3cc4213c7164…
Force block
— not fired
Score recovered
no
Elapsed
—