Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeJapanese Translator Extention
Findings · 3
+2 more findings locked
MEDIUM FINDINGS · 3
  1. 01Mazii session token (tokenId cookie from mazii.net) is read via browser.cookies, AES-decrypted with a hardcoded key, then re-encoded and POSTed to api.mazii.net/api/init-login.
  2. 02User-selected text on any HTTP(S) page is sent to mazii.net / api.mazii.net / translate.googleapis.com when user double-clicks or alt-clicks a word.
  3. 03Every text-selection change on any HTTP(S) page is sent from the content script to the background page (local IPC, no network exfil).
+2 more findings locked
OTHER EXTENSIONS

Is Japanese Translator Extention safe?

Medium risk

No summary available.

Ghi Nguyenv1.4Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+2 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.mazii.dictionary.Mazii-Extension.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact