Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

ImTranslator: Translator, Dictionary, TTS

noaijdpnepcgjemiklgfkcfbkokogabh
Risk Score
2.59
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category TranslationTool
Installs 800,000
Rating 4.4
Last updated 2026-08-03
Manifest version MV3
CSP present ❌ no
Developer support@smartlinkcorp.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension — maps to worst-case privacy score.
  • Broad host permissions (http://*/* + https://*/* + content_scripts <all_urls>) allow reading/modifying every page the user visits.
  • No CSP declared; dom_sink_innerhtml_userctrl in content script with broad host access elevates DOM-XSS risk.
  • new Function() constructor in jscolor.js enables dynamic code execution.
  • 12 distinct external JS hosts contacted including coinbase.com and odvarko.cz — wide network footprint for a translation tool.

Evidence

  • privacy_policy_generic_admits_sharing store Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → worst-case privacy score +10.0 per v3.5(D).
  • broad_host_permissions manifest host_permissions=[http://*/*, https://*/*] + content_scripts on <all_urls>; TranslationTool discount applied (-1.5).
  • no_csp crx content_security_policy is null; MV3 default strict, but dom_sink_innerhtml_userctrl elevates risk under FIX B.
  • dom_sink_innerhtml_userctrl crx translator.js assigns translation response to innerHTML — DOM-XSS sink; csp_present=false triggers +2.0 code quality.
  • function_constructor crx jscolor.js uses new Function() for dynamic code execution (+2.5 code quality).
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; reputation discounts applied, floor at 2.0.
  • external_hosts_diverse crx 12 external hosts incl. commerce.coinbase.com, odvarko.cz; >3 distinct registrable domains (+1.5 network).
  • no_cve_findings crx cve_findings_raw is empty; CVE pillar = 0.0.

Permissions Breakdown

  • scripting medium Can inject JS into pages; paired with <all_urls> host access raises capability significantly.
  • storage low Local settings persistence; low standalone risk.
  • contextMenus low Adds right-click menu items; standard for translation tools.
  • tabs medium Can read tab URLs and metadata across all open tabs.
  • http://*/* high Broad host access to all HTTP sites; content scripts run on <all_urls>.
  • https://*/* high Broad host access to all HTTPS sites including sensitive banking/finance.
  • content_scripts:<all_urls> high Scripts injected on every page the user visits; maximum reach.

Pillar Scores

Permissions4.50
Reputation2.00
Network3.50
Webstore1.50
Maintenance0.00
Privacy10.00
Code Quality3.50
CVE Exposure0.00

Scoring History

%27fsssiedxa xx psssiedx 3.51 Low review 2026-08-22
%27fsssiedxa$"sssiedx 3.78 Low review 2026-08-22
&#x27;fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 2.63 Low review 2026-08-22
&#x22;fsssiedxa&#x27;sssiedx 3.73 Low review 2026-08-22
&#x22;fsssiedxa$'sssiedx 3.54 Low review 2026-08-22
$'fsssiedxasssiedx 3.55 Low review 2026-08-22
fsssiedxa$'sssiedx 3.68 Low review 2026-08-22
<fsssiedxa&#x27;sssiedx 3.68 Low review 2026-08-22
xx pfsssiedxm$'sssiedx 4.03 Medium review 2026-08-20
"fsssiedxm$'sssiedx 2.63 Low review 2026-08-20
&#x27;fsssiedxm"sssiedx 4.08 Medium review 2026-08-20
&#x27;fsssiedxm$"sssiedx 3.48 Low review 2026-08-20
&#x22;fsssiedxm sssiedx 3.78 Low review 2026-08-20
<fsssiedxm&#x22;sssiedx 3.52 Low review 2026-08-20
<fsssiedxm$"sssiedx 2.59 Low review 2026-08-20
<fsssiedxh xx psssiedx 3.46 Low review 2026-08-20
<fsssiedxh$"sssiedx 3.62 Low review 2026-08-20
<fsssiedx{"sssiedx 4.37 Medium review 2026-08-20
<fsssiedxg&#x27;sssiedx 4.02 Medium review 2026-08-19
xx pfsssiedxn$"sssiedx 4.03 Medium review 2026-08-19
%27fsssiedxn$"sssiedx 3.60 Low review 2026-08-19
&#x27;fsssiedxn$"sssiedx 3.53 Low review 2026-08-19
<fsssiedxn sssiedx 3.59 Low review 2026-08-19
<fsssiedx{&#x22;sssiedx 3.64 Low review 2026-08-19
<fsssiedxa'sssiedx 2.54 Low review 2026-08-07
<fsssiedxa&#x22;sssiedx 3.70 Low review 2026-08-07
<fsssiedxa$'sssiedx 3.74 Low review 2026-08-07
xx pfsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 2.63 Low review 2026-08-07
%27fsssiedxa"sssiedx 3.56 Low review 2026-08-07
&#x27;fsssiedxa sssiedx 3.56 Low review 2026-08-07
&#x22;fsssiedxa sssiedx 3.71 Low review 2026-08-07
fsssiedxa$"sssiedx 2.68 Low review 2026-08-07
<fsssiedxa$"sssiedx 3.38 Low review 2026-08-07
fsssiedxa<sssiedx 4.12 Medium review 2026-08-07
xx pfsssiedxm$"sssiedx 4.19 Medium review 2026-07-30
%22fsssiedxm$"sssiedx 2.72 Low review 2026-07-30
&#x27;fsssiedxm'sssiedx 3.77 Low review 2026-07-30
3.77 Low review 2026-07-30
<fsssiedxm$'sssiedx 3.77 Low review 2026-07-30
<fsssiedxf&#x27;sssiedx 3.79 Low review 2026-07-30
<fsssiedx{ sssiedx 3.77 Low review 2026-07-30
<fsssiedx{&#x27;sssiedx 3.76 Low review 2026-07-30
fsssiedx<sssiedx 3.62 Low review 2026-07-30
<fsssiedx{'sssiedx 3.62 Low review 2026-07-30
<fsssiedx{$'sssiedx 3.78 Low review 2026-07-30
<fsssiedx{fdsaxax><!--></ScRiPt>asddsssiedx 3.73 Low review 2026-07-30
<fsssiedx{ 3.73 Low review 2026-07-30
<fsssiedx{$"sssiedx 3.78 Low review 2026-07-30
fsssiedxdfdsaxax><!--></ScRiPt>asddsssiedx 3.62 Low review 2026-07-30
fsssiedxd"sssiedx 2.63 Low review 2026-07-30
fsssiedxd 3.86 Low review 2026-07-30
sssieddrubricxsx 2.63 Low review 2026-07-30
v3.6 2.59 Low review 2026-06-16
v3.4-rev 4.59 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:59
Listing SHA 5cb5a45199d5…
Force block — not fired
Score recovered no
Elapsed 27.7s