Wordigo - Translator, Dictionary, TTSSecurity Analysis

Chromev0.0.17MV3March 4, 2026 at 03:38 AM
Potentially unsafe

This extension shows concerning patterns that may indicate risky behavior. Proceed with caution.

7.4HIGH
7.4 HIGH

This extension shows significant risk signals. Review the findings below carefully before installing or continuing to use it.

Based on 5 permissions including high-risk ones, 32 code findings, 2 dangerous combinations.

Trust Signals(1.0/10)

Users
387
Rating
3.9(4 reviews)
Status
Featured

Dangerous Combinations(2)

HIGHCookie access + external network

Extension has cookie access and sends data to external servers — potential session token theft.

cookies+external network request
CRITICALAll-sites access + keyboard capture

Extension has access to all sites and captures keyboard input — behavior consistent with a keylogger.

<all_urls>+keylogger_pattern
Permissions
7.0/10
Code
8.2/10
Combinations
10.0/10
Manifest/CSP
3.1/10

Permissions(5 analyzed)

Code Findings(11 patterns, 32 total)

Libraries(2 detected)

2 libraries detected

Content Security Policy

No CSP Defined(1 issue)
MEDIUM
N/ANo CSP defined

This extension does not define a Content Security Policy. A CSP helps prevent XSS and code injection attacks.

Manifest Analysis(1 finding)

Resolved from __MSG_* i18n placeholders:

Description: Wordigo: Translate text in the browser and add it to the dictionary. Easily bypass language restrictions..

MEDIUM
content_scriptsContent script injected on all URLs

Content script matches <all_urls>, executing on every website the user visits.

External Domains(8)

api.wordigo.appapp.formbricks.comfb.mefeross.orggithub.comlocalhostreactjs.orgwordigo.app

Indicators of Compromise

1541 indicators of compromise found

File Statistics

18
Total Files
5
JS Files
4.8 MB
Total Size

Other Scanned Extensions