Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeNextWord Translate
Findings · 3
MEDIUM FINDINGS · 3
  1. 01Google Analytics (UA-117245981-5) loaded into background page, fired on every translate / voice / popup / setting interaction with an encoded userStatus bitstring carrying login + subscription state
  2. 02Background page auto-fetches a language config from third-party host api.eportalmobile.com on every extension load, and posts user feedback to the same host — neither matches the vendor's stated domain (nextword.me) nor the publisher (MOBIPRO EDUCATION LLC)
  3. 03Auth token (_tk_ cookie) embedded directly in URL query string on every authenticated nextword.me request, so it appears in server access logs / Referer headers / browser history
OTHER EXTENSIONS

Is NextWord Translate safe?

Medium risk

No summary available.

Learning languages when browsing, speed-up your reading, turn every webpage to bilingual.v1.0.1Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026com.ume.nextword.translate.extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact