Is Translate for Chrome -Translator, Dictionary safe?

Medium risk

Translate for Chrome -Translator, Dictionary is medium risk. The image OCR/translation feature uploads a PNG of your selected area to backenster.com, a third-party backend unnamed in the listing.…

Translator App.v1.0.4Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Screen-area screenshots sent to backenster.com with shared hardcoded token

The image OCR/translation feature uploads a PNG of your selected area to backenster.com, a third-party backend unnamed in the listing.

It uses a hardcoded bearer token, same for every user, with `credentials:'include'`, sending cookies too.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You click the Image OCR button in the translator popup and drag to select a region of the page.

The extension captures a full-tab screenshot, crops it to your selected rectangle, and converts it to a PNG blob.

The extension did this

The PNG is immediately POSTed to backenster.com with a hardcoded bearer token shared by all users.

The request includes credentials: 'include', so any cookies for backenster.com travel with the image.

02EvidenceNETWORK CAPTURE
Captured request
POSThttps://backenster.com/v2/api/v3/parseImage?platform=android&compose=true
JSON with fields: err (null on success), sourceData (array of OCR'd text strings), translatedData (array of translated strings).
Headers
acceptapplication/json
authorizationBearer sdf2fsd34lkkdfg
referrer-policystrict-origin-when-cross-origin
Body
[multipart/form-data] from=en&to=fr&file=<PNG binary, cropped screenshot region>
03EvidenceCODE COMPARE
The code that does this

Service worker: image upload to backenster.com (bg.js vs bg_readable.js)

What it actually does
const n = new FormData;
n.append("from", t.langSrc);
n.append("to", t.langDst);
n.append("file", e, "filename.png");
fetch("https://backenster.com/v2/api/v3/parseImage?platform=android&compose=true", {
    method: "POST",
    headers: {
        authorization: "Bearer sdf2fsd34lkkdfg",
        accept: "application/json"
    },
    body: n,
    credentials: "include",
    referrerPolicy: "strict-origin-when-cross-origin"
})
04EvidenceTHIRD PARTY LIST
Destination for image data
  • backenster.com

    Receives cropped screenshots for OCR processing and returns extracted + translated text. Also receives per-installation UUID and app key for config fetch (api/app/config).

What it can do

Permissions this extension asks for, as declared in version 1.0.4. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    <all_urls>

  • Add items to the right-click menu

    contextMenus

  • Store data in your browser

    storage

  • See the address and title of every tab you have open

    tabs

Updated 30 September 2026elpmkbbdldhoiggkjfpgibmjioncklbn