Is TransOver safe?
TransOver lets any webpage trigger Google Translate requests and read returned translations from its injected popup.
TransOver injects a content script on all pages and accepts same-window postMessage requests without an origin check, then asks Google Translate to translate the supplied text. The translation is rendered in a transover-popup element with an open shadow root, so page scripts can read the returned text. Pages can also send a message that stores the extension's global disabled setting.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 1.74. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on translate.googleapis.com
https://translate.googleapis.com/*
Read and change your data on clients5.google.com
https://clients5.google.com/*
Read and change your data on www.google-analytics.com
https://www.google-analytics.com/*
Store data in your browser
storage
Where it sends data
Destinations our analysis observed TransOver contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- translate.googleapis.comwidely used
TransOver sends data to translate.googleapis.com. A widely used service: 86 other extensions we have analysed send data here.
- clients5.google.com
TransOver sends data to clients5.google.com. 3 other extensions we have analysed send data here.