Firefox Add-ons
1Versions
0Code reviewed

Not reviewed

No code review on record

We have not reviewed this extension’s code, so we cannot vouch for it either way. Check the permissions below to decide whether it asks for more than it needs.

Want us to read this extension's code? Ask for a review and we'll queue it.

101 indicators in this extension

101 indicators
0 versions analysed

Every finding is verified by a security analyst. Unlock the code evidence, indicators and version history.

Unlock this report — $4.99Start 7-day trial — all reports
One-time payment · Secure checkout by Stripe

What our analysis found

DeepL, used by 2,389 people, is not yet reviewed by Extension Auditor. Its permissions mean it can read and change data on all websites, can inject scripts into pages and can observe network requests. It comes from a trusted publisher and was last updated in June 2026.

DeepL Firefox extension security report

ID: deepl-translate-in-page

Extension Info & Metadata

Status
Active
Version
2.10
Size
3.94 MB
Rating
3.9/5
Reviews
15
Users
2,389
Type
Extension
Updated
Jun 6, 2026
Category
N/A
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
No
This publisherTrack record
4extensions
All still listed

Publisher Contextual Analysis

Trusted
Author
DeepL
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Extensions
4
Active
2
Obsolete
0
Listed
4
Unlisted
0
Users
326,942

Install growth

Item
Type
Severity
Description
scripting
Permission
Critical
This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to.
webRequest
Permission
Critical
This permission enables the extension to monitor and analyze all web requests made by the browser. Rated Critical because it can observe all network traffic including sensitive data, track browsing behavior, and gather authentication tokens.
webRequestBlocking
Permission
Critical
This permission allows the extension to intercept, modify, or block any web request in real-time before it reaches its destination. Rated Critical because it can modify sensitive data (like passwords, credit cards) before encryption, redirect traffic to malicious sites, or block security updates.
declarativeNetRequest
Permission
Critical
This permission allows the extension to define rules to block, redirect, or modify network requests. Rated Critical because it can control all network traffic, potentially blocking security updates or redirecting to malicious sites.
<all_urls>
Host
Critical
Broad host access — the extension can read/modify content on every website.
*://*/*
Host
Critical
Broad host access — the extension can read/modify content on every website.
Dangerous Permission Combination: scripting,<all_urls>,webRequest
Risk Factor
Critical
Enables sophisticated data theft through script injection and traffic monitoring
Dangerous Permission Combination
Risk Factor
Critical
This extension can intercept, modify, and block web requests in real-time.
identity
Permission
High
This permission accesses Chrome identity service and user information. Rated High because it can obtain OAuth tokens, access connected accounts, and impersonate the user in authenticated service.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 25% increase: Unsafe code evaluation capabilities increase attack surface
Broad Host Permissions
Risk Factor
High
This extension has broad host permissions allowing it to access many or all websites.
Broad Content Script Access
Risk Factor
High
This extension can inject scripts into any website.
Unsafe WebAssembly Execution
Risk Factor
High
This extension's CSP allows "wasm-unsafe-eval".
activeTab
Permission
Medium
This permission grants temporary access to the current tab. Rated Medium because it can access current page content when invoked, though limited to user-initiated actions.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
alarms
Permission
Low
This permission schedules periodic tasks. Rated Low because it can only trigger events at specified times without access to sensitive data.
contextMenus
Permission
Low
This permission adds items to browser context menus. Rated Medium because it only modifies right-click menus without access to page content.

101 indicators in this extension

101 indicators
0 versions analysed

Every finding is verified by a security analyst. Unlock the code evidence, indicators and version history.

Unlock this report — $4.99Start 7-day trial — all reports
One-time payment · Secure checkout by Stripe

About this extension

DeepL's Language AI delivers unmatched translation accuracy and writing assistance. Translate pages, emails and docs seamlessly with top-tier data security.

User reviews

Extension files

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.

URLs
101

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

No URLs found
No IP addresses found

101 indicators in this extension

101 indicators
0 versions analysed

Every finding is verified by a security analyst. Unlock the code evidence, indicators and version history.

Unlock this report — $4.99Start 7-day trial — all reports
One-time payment · Secure checkout by Stripe
Version
Size
Verdict
Findings
Permhash
2.10
Latest
3.94 MBNot scanned—
89a4746bdf22acdc27116a0232d11efd9b20d5eac13223dbdf63be9f25bb05d4
Showing 1 to 1 of 10 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.