Read Frog translates web pages for people learning a language, not just reading one. Its bilingual mode places each translated paragraph under the original so you can compare them, and a translation-only mode replaces the text for plain reading. Select any phrase for a toolbar that translates it, explains it at your level, or reads it aloud with free Edge TTS voices in more than 80 languages. It also translates YouTube subtitles in the player.
It is on this list for how it uses AI. A context-aware mode sends the page title and a condensed Markdown version of the page along with each passage, so technical terms and idioms translate correctly; requests are batched to cut API costs; and it works with more than 20 providers, including OpenAI, Anthropic, Gemini, DeepSeek, Groq and a local Ollama model, or with free Google, Microsoft and DeepLX translation. Custom AI actions, a vocabulary notebook called Notebase and spaced-repetition flashcards turn what you read into study material.
Read Frog, or 陪读蛙 in Chinese, is developed by mengxi-ream and contributors, has about 10,000 stars and is dual-licensed under GPL-3.0 and a commercial licence. It updates frequently; version 1.50.0 was released on October 2, 2026.
- Repository: github.com/mengxi-ream/read-frog
- Licence: GPL-3.0 (GNU General Public License v3.0)
- Language: TypeScript. Stars: 9,956. Forks: 743. Last push: Oct 3, 2026.
- Scan: safe, Oct 3, 2026, commit ab7e2ad
Who it is for
Language learners who read news, articles and documentation in their target language, and anyone who wants immersive bilingual translation with a choice of AI model instead of a fixed service.
Getting started
1. Install from the Chrome Web Store
open https://chromewebstore.google.com/detail/read-frog-open-source-ai/modkelfkcfjpgbfmnbnllalkiogfofhb2. Or for Firefox (an Edge add-on is listed in the README too)
open https://addons.mozilla.org/firefox/addon/read-frog-open-ai-translator/3. Open the options, choose your languages, and pick Google or Microsoft (free) or add an AI provider key
# Read Frog icon > Options > ProvidersFree Google and Microsoft translation works without a key. AI translation and explanations use your own provider key and are billed by that provider; with context-aware mode on, a condensed copy of each page is sent along with the text. Usage analytics are on by default in Chrome and Edge and off by default in Firefox; the switch is in the options.
Safety scan
We cloned mengxi-ream/read-frog at commit ab7e2ad on Oct 3, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.
- One secret hit: src/utils/host/translate/api/google.ts line 13, a Google API key for translate-pa.googleapis.com with client wt_lib. That is the public key of Google's own website-translation widget, embedded so the free Google provider works without your own key; it is not a Read Frog credential. No pattern hits, bare-IP URLs or binaries across 1,808 files and about 344,000 lines, 290,000 of them TypeScript.
- We read the analytics code. posthog-js is enabled by default except in the Firefox build (getDefaultAnalyticsEnabled returns false there), sends feature_used events at most once per day per feature, strips provider options and configuration from the properties, and can attach a site_domain. The toggle is stored in the extension's settings.
- 94 known advisories, none critical (48 high), in pnpm-lock.yaml (1,454 packages). Much is development tooling: adm-zip via the Firefox test runner, axios via the nx build system, brace-expansion and braces. At run time, @xmldom/xmldom 0.9.10 (11 high) arrives with mathml-to-latex, which converts math on pages; its issues are validation bypasses and slow parsing of crafted XML, so a hostile page could at worst slow the extension.
- 8 workflows. Two use pull_request_target: lint-pr checks the pull request title, and pr-contributor-trust checks out the base commit before running its script, so neither executes pull request code. None of the 7 third-party actions is pinned to a commit.
- Dependabot, licence and contributing guide present; no security policy or CodeQL. The npm hooks run wxt prepare and Husky, both local.
What the scanner counted
| Check | Result |
|---|---|
| Secrets | 1 candidate found and read; see the notes above. |
| Suspicious code | None found. |
| Install-time code | 2 npm lifecycle scripts |
| Committed binaries | None. |
| CI workflows | 8 workflows. 2 use pull_request_target, none check out the pull request head. 7 of 7 third-party actions pinned to a tag rather than a commit. |
| Network hosts | 40 distinct hosts referenced from source; most often api.openai.com, deeplx.vercel.app, api.custom.com, api.jalapeno-cloud.ai. No URLs to bare IP addresses. |
| Known vulnerabilities | 94 advisories across 1,454 pinned packages: 0 critical, 48 high, 40 moderate, 6 low. pnpm-lock.yaml: 1,454 packages, 94 advisories. |
| Project hygiene | Has automated dependency updates, licence file, contributing guide. Missing security policy, CodeQL. |
| OpenSSF Scorecard | Not scored: the project is not in Scorecard's weekly index. |
The raw findings
Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.
Secret candidates (1, redacted)
| Where | Rule | Match |
|---|---|---|
| src/utils/host/translate/api/google.ts:13 | google-api-key | AIzaSy…520 (39 chars) |
npm lifecycle scripts (2)
package.jsonpostinstall:WXT_SKIP_ENV_VALIDATION=true wxt preparepackage.jsonprepare:husky
Worst known vulnerabilities (24 of 94)
| Advisory | Severity | Package | Summary |
|---|---|---|---|
| GHSA-27p8-2357-5qqv | high | @xmldom/xmldom@0.9.10 | xmldom: DocType `name` Injection Bypasses requireWellFormed |
| GHSA-3px3-54cx-rmw9 | high | @xmldom/xmldom@0.9.10 | xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the… |
| GHSA-4w3w-2rp5-g8jm | high | @xmldom/xmldom@0.9.10 | xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed |
| GHSA-6mj3-qw4j-hgrw | high | @xmldom/xmldom@0.9.10 | xmldom: HTML raw-text closing-tag case mismatch causes output amplification |
| GHSA-8344-3jmq-59r6 | high | @xmldom/xmldom@0.9.10 | xmldom: Quadratic-time attribute deduplication |
| GHSA-93r5-fhx6-vmg9 | high | @xmldom/xmldom@0.9.10 | xmldom: Quadratic-time parsing via the malformed-input recovery path - `parseElementStartPart` re-scan and `normalize()`… |
| GHSA-965w-775f-mr7g | high | @xmldom/xmldom@0.9.10 | xmldom: Quadratic-memory consumption |
| GHSA-c7q8-3ch8-vqpv | high | @xmldom/xmldom@0.9.10 | xmldom: Processing Instruction Target Injection Bypasses requireWellFormed |
| GHSA-g53g-w8rj-fmg7 | high | @xmldom/xmldom@0.9.10 | xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instructions |
| GHSA-vr34-hp96-76pp | high | @xmldom/xmldom@0.9.10 | xmldom: requireWellFormed DocType publicId/systemId validation is bypassable via an embedded line terminator |
| GHSA-w2rr-34g9-rvrj | high | @xmldom/xmldom@0.9.10 | xmldom: Element name injection via createElement() bypasses requireWellFormed |
| GHSA-7q85-xj36-vmfc | high | adm-zip@0.6.0 | adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS) |
| GHSA-8238-w5pm-2374 | high | adm-zip@0.6.0 | adm-zip: Unhandled error event in async DEFLATE decompression crashes Node.js process (DoS) |
| GHSA-j5f4-cc29-5x44 | high | adm-zip@0.6.0 | adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation |
| GHSA-rcw4-f5rp-g42v | high | adm-zip@0.6.0 | adm-zip: Decompression-bomb protection (fix for CVE-2026-39244) can be bypassed by declaring uncompressed size as 0 |
| GHSA-3pq3-5fj3-cg6v | high | axios@1.18.1 | Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls |
| GHSA-542g-h47m-68v8 | high | axios@1.18.1 | Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization |
| GHSA-c29m-xwm3-cm6r | high | axios@1.18.1 | Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS) |
| GHSA-m8m8-qj5v-23w3 | high | axios@1.18.1 | Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection |
| GHSA-mghh-pgcx-3jjj | high | axios@1.18.1 | Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location |
| GHSA-r4gj-5m52-g5wh | high | axios@1.18.1 | Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF |
| GHSA-x97p-jq2g-jp4f | high | axios@1.18.1 | Axios: Prototype Pollution Gadget in axios toFormData Options |
| GHSA-3jxr-9vmj-r5cp | high | brace-expansion@1.1.15 | brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups |
| GHSA-6j4f-fj2g-mc7p | high | brace-expansion@1.1.15 | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion |
Workflows worth a look
- .github/workflows/lint-pr.yml: pull_request_target
- .github/workflows/pr-contributor-trust.yml: pull_request_target
By the numbers
| Stars | 9,956 |
|---|---|
| Forks | 743 |
| Contributors | 65 |
| Commits | 1,216 |
| Open issues | 77 |
| Open pull requests | 1 |
| Releases | 236 |
| Latest release | v1.50.0 |
| Licence | GPL-3.0 |
| Main language | TypeScript |
| Project age | 1 year |
| Last push | Oct 3, 2026 |
| Tracked files | 1,808 |
| Lines of code | 344.2K |
| Checkout size | 42 MB |
Lines by language: TypeScript 289.6K, Markdown 24K, YAML 20.1K, JSON 5,353, JavaScript 3,276, CSS 969.
Questions
Is Read Frog free?
Yes. The extension is free in the Chrome, Edge and Firefox stores and the code is GPL-3.0, also available under a commercial licence for closed-source use. Google, Microsoft and DeepLX translation and Edge TTS voices cost nothing; AI providers bill you through your own API key, or nothing with a local Ollama model.
Which AI models does Read Frog support?
More than 20 providers through the Vercel AI SDK, including OpenAI, Anthropic Claude, Google Gemini, DeepSeek, xAI Grok, Groq, Mistral and Ollama, plus custom endpoints with your own model settings.
Can Read Frog translate YouTube videos?
It translates YouTube subtitles inside the player, showing the translation alongside the original captions. It does not dub audio; for videos without captions, there is nothing for it to translate.
This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.
