Is Image Translator - Comics Translator | Manga Translator safe?

Medium risk

Image Translator is medium risk. On every startup, Image Translator sends your Google email to livepolls.app as a persistent user ID for Alibaba Cloud ARMS telemetry, with no prompt. Dynamic analysis captured the email in the URL and POST body.

livepolls.appv6.8.4Chrome Web Store
47Risk
Who publishes it

livepolls.app - 10 other listings from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
livepolls.app

Shared hosts - 1 hostname

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

log.aibabygenerator.io
Also called by 1 other listing: YouTube Translator

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Google account email sent to livepolls.app and Alibaba ARMS on startup

On every startup, Image Translator sends your Google email to livepolls.app as a persistent user ID for Alibaba Cloud ARMS telemetry, with no prompt.

Dynamic analysis captured the email in the URL and POST body.

Severity
Medium unwanted
Type
Unexpected
CWE
CWE-359
Source
Dynamic sandbox
What actually happens
You did this

You open your browser with the Image Translator extension installed.

No action is required, the collection happens on every startup automatically.

The extension did this

The extension reads your Google account email via a Chrome identity API and transmits it to the developer's server and an Alibaba Cloud analytics service.

The email is sent in plain text in both the URL query string and the POST body of the livepolls.app request.

Captured request
POSThttps://www.livepolls.app/image_translator/api/user/status?email=robertfinwitch@gmail.com

HTTP 200, returns JWT and user profile used to gate translation quotas

Headers
Referer
https://www.livepolls.app/image_translator_chrome
Content-Type
application/x-www-form-urlencoded; charset=UTF-8
X-Access-Channel
image_translator
Body
email=robertfinwitch@gmail.com&app_type=chrome_addon&uuid=107890220540720092498
Fields sent in the livepolls.app request
  • Google account email
    robertfinwitch@gmail.com

    Your primary Google account address, sent as a persistent identifier to the developer's server on every startup.

  • Google account ID
    107890220540720092498

    Your permanent numeric Google account ID, sent as the 'uuid' field alongside the email.

  • Client type
    chrome_addon

    Tells the server which browser addon is making the request.

What's stored on your device

Email and account ID sit in synced storage, readable by any component without re-calling the identity API, and synced across devices.

Location
chrome.storage.sync key 'g_user_info'
Contents
{  "id": "107890220540720092498",  "email": "robertfinwitch@gmail.com"}
The code that does this

Background service worker, identity collection and server transmission

Readable version

getOrFetchUserInfo() — retrieves Google account identity

function getOrFetchUserInfo() {  return new Promise(async (resolve, reject) => {    let cached = await chrome.storage.sync.get(['g_user_info']);    if (cached.g_user_info) {      resolve(cached.g_user_info);    } else {      chrome.identity.getProfileUserInfo({ accountStatus: 'ANY' }, userInfo => {        resolve(userInfo);        chrome.storage.sync.set({ g_user_info: userInfo });      });    }  });}

sendEmailToServer() — POSTs email to livepolls.app

// Inside the user-status fetch:const response = await fetchJson({  url: `https://www.livepolls.app/image_translator/api/user/status?email=${userInfo.email}`,  method: 'POST',  headers: {    Referer: 'https://www.livepolls.app/image_translator_chrome',    'Content-Type': 'application/x-www-form-urlencoded; charset=UTF-8'  },  data: {    email: userInfo.email,    app_type: 'chrome_addon',    uuid: userInfo.id   // Google account numeric ID  }});

onInstalled — runs on every startup

chrome.runtime.onInstalled.addListener(async (details) => {  createContextMenu();  if (details.reason === chrome.runtime.OnInstalledReason.INSTALL) {    chrome.tabs.create({ url: '/src/pages/welcome/index.html' });  }  sendEmailToServer();          // immediate transmission  const userInfo = await getOrFetchUserInfo();  chrome.storage.sync.set({ g_user_info: userInfo }); // cache for content scripts});
The code that does this

Content script, ARMS SDK initialised with email as uid

Readable version

ARMS SDK — email used as persistent user identifier

// Every error/event logged to Alibaba Cloud ARMS is tagged with the// user's Google email as uid, making all telemetry cross-correlatable:const initArms = (email) => armsSDK.singleton({  pid: 'aa9hucpddy@f07435a50fe14e0',  // developer's ARMS project ID  uid: email,                           // Google account email as user ID  appType: 'web',  imgUrl: 'https://arms-retcode.aliyuncs.com/r.png?'});function logBgTranslateEvent(data) {  chrome.storage.sync.get(['g_user_info']).then(({ g_user_info }) => {    const arms = initArms(g_user_info.email);    arms.sum('bgTranslate', 1);    arms.error(new Error(JSON.stringify(data)), { filename: 'bgTranslate', lineno: 384 });  });}
Destinations that receive the Google account email
    • www.livepolls.app

    Developer's own service. Receives email and account ID via POST each startup to authenticate and gate translation quota. Operator: livepolls.app (unknown entity).

    • arms-retcode.aliyuncs.com

    Alibaba Cloud ARMS telemetry. Receives the email as the 'uid' parameter in beacons triggered by translation events. Operator: Alibaba Group, China.

What it can do

Permissions this extension asks for, as declared in version 6.7.7. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 6.8.4, which we have not unpacked yet.

  • Read and change your data on every site you visit

    http://*/*

  • Read and change your data on every secure site you visit

    https://*/*

  • Show a panel beside the page

    sidePanel

  • Sign you in with your Google account

    identity

  • See the email address of your Google account

    identity.email

  • Store data in your browser

    storage

  • Add items to the right-click menu

    contextMenus

  • Run its own code inside the pages you visit

    scripting

  • Act on the current tab, but only after you click the extension

    activeTab

Updated 30 September 2026pbhpcbdjngblklnibanbkgkogjmbjeoe