CRX aminer
Extension icon

JP English Dictionary: English to 200 Languages

Version 1.1.2 View in Chrome Web Store

Last scanned: about 2 hours ago

Extension Details

Developer: jpdictionary.com
Rating: 5.0 ★ (1.2K ratings)
Users: 4,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has a perfect 5.0 rating with 1,200 reviews and 4,000 users, which suggests positive user experiences. However, the developer information is minimal, with only a website domain provided (jpdictionary.com) and no established company reputation or transparency about the development team.

Concerns:

The extension's permissions are extremely excessive for a dictionary tool. The combination of broad host permissions, content script injection across all websites, and unsafe WebAssembly execution creates a dangerous attack surface. A dictionary extension should not need to track web navigation, access all tabs, or inject scripts into every website you visit. The 'wasm-unsafe-eval' policy is particularly concerning as it allows execution of potentially obfuscated malicious code. These permissions would allow the extension to monitor your entire browsing activity, steal credentials from any website, and potentially perform cryptocurrency mining or other resource-intensive operations without your knowledge.

Recommendations:

Do not install this extension due to its critical risk level. If you absolutely need this specific dictionary functionality, create a separate Chrome profile with no sensitive accounts or data, and only use it for translation purposes. Consider alternative dictionary extensions with more reasonable permissions, or use web-based translation services instead. The excessive permissions far exceed what's necessary for language translation functionality.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
Unsafe WebAssembly Execution
This extension's Content Security Policy allows 'wasm-unsafe-eval', which permits potentially dangerous WebAssembly code execution. This could be used to hide malicious code or perform CPU-intensive operations.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.