CRX aminer
Extension icon

JP English Dictionary: English to 200 Languages

Version 1.1.2 View in Chrome Web Store

Last scanned: about 11 hours ago

Extension Details

Developer: jpdictionary.com
Rating: 5.0 ★ (1.3K ratings)
Users: 4,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has a perfect 5.0 rating with 1,300 reviews and 4,000 users, suggesting positive user experiences. The developer operates from jpdictionary.com, indicating a dedicated domain for the service. However, the relatively small user base for a translation tool raises questions about its necessity compared to established alternatives like Google Translate.

Concerns:

The extension's permissions are severely excessive for a dictionary application. The combination of broad host permissions with content script injection across all websites creates significant privacy and security risks. The webNavigation permission allows comprehensive browsing tracking, while the unsafe WebAssembly execution policy could hide malicious code. Most concerning is that a simple dictionary tool has no legitimate need to access all websites, manipulate tabs, or track navigation patterns.

The technical implementation suggests capabilities far beyond translation services, including potential data harvesting, credential theft, and comprehensive user surveillance. The Content Security Policy allowing unsafe WebAssembly execution is particularly alarming as it enables sophisticated attack vectors.

Recommendations:

Do not install this extension. Use established translation services like Google Translate, Microsoft Translator, or browser-native translation features instead. If you must use this extension, run it in a completely isolated Chrome profile with no access to sensitive accounts or data. Consider that the excessive permissions indicate potential malicious intent disguised as a legitimate dictionary service.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
Unsafe WebAssembly Execution
This extension's Content Security Policy allows 'wasm-unsafe-eval', which permits potentially dangerous WebAssembly code execution. This could be used to hide malicious code or perform CPU-intensive operations.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.