5 min read

Read Frog: AI Bilingual Translation for Learning Languages (GitHub, Scanned)

A browser extension that translates pages side by side with AI and turns what you read into flashcards.

Read Frog logo
✅
Scan: safe. Nothing malicious. One thing to know: usage analytics, which can include the domain of the site where you used a feature, go to PostHog by default in Chrome and Edge (off by default in Firefox), with a switch in the options. Scanned Oct 3, 2026; the full report is below.

Read Frog translates web pages for people learning a language, not just reading one. Its bilingual mode places each translated paragraph under the original so you can compare them, and a translation-only mode replaces the text for plain reading. Select any phrase for a toolbar that translates it, explains it at your level, or reads it aloud with free Edge TTS voices in more than 80 languages. It also translates YouTube subtitles in the player.

It is on this list for how it uses AI. A context-aware mode sends the page title and a condensed Markdown version of the page along with each passage, so technical terms and idioms translate correctly; requests are batched to cut API costs; and it works with more than 20 providers, including OpenAI, Anthropic, Gemini, DeepSeek, Groq and a local Ollama model, or with free Google, Microsoft and DeepLX translation. Custom AI actions, a vocabulary notebook called Notebase and spaced-repetition flashcards turn what you read into study material.

Read Frog, or 陪读蛙 in Chinese, is developed by mengxi-ream and contributors, has about 10,000 stars and is dual-licensed under GPL-3.0 and a commercial licence. It updates frequently; version 1.50.0 was released on October 2, 2026.

  • Repository: github.com/mengxi-ream/read-frog
  • Licence: GPL-3.0 (GNU General Public License v3.0)
  • Language: TypeScript. Stars: 9,956. Forks: 743. Last push: Oct 3, 2026.
  • Scan: safe, Oct 3, 2026, commit ab7e2ad

Who it is for

Language learners who read news, articles and documentation in their target language, and anyone who wants immersive bilingual translation with a choice of AI model instead of a fixed service.

Getting started

1. Install from the Chrome Web Store

open https://chromewebstore.google.com/detail/read-frog-open-source-ai/modkelfkcfjpgbfmnbnllalkiogfofhb

2. Or for Firefox (an Edge add-on is listed in the README too)

open https://addons.mozilla.org/firefox/addon/read-frog-open-ai-translator/

3. Open the options, choose your languages, and pick Google or Microsoft (free) or add an AI provider key

# Read Frog icon > Options > Providers

Free Google and Microsoft translation works without a key. AI translation and explanations use your own provider key and are billed by that provider; with context-aware mode on, a condensed copy of each page is sent along with the text. Usage analytics are on by default in Chrome and Edge and off by default in Firefox; the switch is in the options.

Safety scan

We cloned mengxi-ream/read-frog at commit ab7e2ad on Oct 3, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • One secret hit: src/utils/host/translate/api/google.ts line 13, a Google API key for translate-pa.googleapis.com with client wt_lib. That is the public key of Google's own website-translation widget, embedded so the free Google provider works without your own key; it is not a Read Frog credential. No pattern hits, bare-IP URLs or binaries across 1,808 files and about 344,000 lines, 290,000 of them TypeScript.
  • We read the analytics code. posthog-js is enabled by default except in the Firefox build (getDefaultAnalyticsEnabled returns false there), sends feature_used events at most once per day per feature, strips provider options and configuration from the properties, and can attach a site_domain. The toggle is stored in the extension's settings.
  • 94 known advisories, none critical (48 high), in pnpm-lock.yaml (1,454 packages). Much is development tooling: adm-zip via the Firefox test runner, axios via the nx build system, brace-expansion and braces. At run time, @xmldom/xmldom 0.9.10 (11 high) arrives with mathml-to-latex, which converts math on pages; its issues are validation bypasses and slow parsing of crafted XML, so a hostile page could at worst slow the extension.
  • 8 workflows. Two use pull_request_target: lint-pr checks the pull request title, and pr-contributor-trust checks out the base commit before running its script, so neither executes pull request code. None of the 7 third-party actions is pinned to a commit.
  • Dependabot, licence and contributing guide present; no security policy or CodeQL. The npm hooks run wxt prepare and Husky, both local.

What the scanner counted

CheckResult
Secrets1 candidate found and read; see the notes above.
Suspicious codeNone found.
Install-time code2 npm lifecycle scripts
Committed binariesNone.
CI workflows8 workflows. 2 use pull_request_target, none check out the pull request head. 7 of 7 third-party actions pinned to a tag rather than a commit.
Network hosts40 distinct hosts referenced from source; most often api.openai.com, deeplx.vercel.app, api.custom.com, api.jalapeno-cloud.ai. No URLs to bare IP addresses.
Known vulnerabilities94 advisories across 1,454 pinned packages: 0 critical, 48 high, 40 moderate, 6 low. pnpm-lock.yaml: 1,454 packages, 94 advisories.
Project hygieneHas automated dependency updates, licence file, contributing guide. Missing security policy, CodeQL.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

The raw findings

Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.

Secret candidates (1, redacted)
WhereRuleMatch
src/utils/host/translate/api/google.ts:13google-api-keyAIzaSy…520 (39 chars)
npm lifecycle scripts (2)
  • package.json postinstall: WXT_SKIP_ENV_VALIDATION=true wxt prepare
  • package.json prepare: husky
Worst known vulnerabilities (24 of 94)
AdvisorySeverityPackageSummary
GHSA-27p8-2357-5qqvhigh@xmldom/xmldom@0.9.10xmldom: DocType `name` Injection Bypasses requireWellFormed
GHSA-3px3-54cx-rmw9high@xmldom/xmldom@0.9.10xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the…
GHSA-4w3w-2rp5-g8jmhigh@xmldom/xmldom@0.9.10xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed
GHSA-6mj3-qw4j-hgrwhigh@xmldom/xmldom@0.9.10xmldom: HTML raw-text closing-tag case mismatch causes output amplification
GHSA-8344-3jmq-59r6high@xmldom/xmldom@0.9.10xmldom: Quadratic-time attribute deduplication
GHSA-93r5-fhx6-vmg9high@xmldom/xmldom@0.9.10xmldom: Quadratic-time parsing via the malformed-input recovery path - `parseElementStartPart` re-scan and `normalize()`…
GHSA-965w-775f-mr7ghigh@xmldom/xmldom@0.9.10xmldom: Quadratic-memory consumption
GHSA-c7q8-3ch8-vqpvhigh@xmldom/xmldom@0.9.10xmldom: Processing Instruction Target Injection Bypasses requireWellFormed
GHSA-g53g-w8rj-fmg7high@xmldom/xmldom@0.9.10xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instructions
GHSA-vr34-hp96-76pphigh@xmldom/xmldom@0.9.10xmldom: requireWellFormed DocType publicId/systemId validation is bypassable via an embedded line terminator
GHSA-w2rr-34g9-rvrjhigh@xmldom/xmldom@0.9.10xmldom: Element name injection via createElement() bypasses requireWellFormed
GHSA-7q85-xj36-vmfchighadm-zip@0.6.0adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)
GHSA-8238-w5pm-2374highadm-zip@0.6.0adm-zip: Unhandled error event in async DEFLATE decompression crashes Node.js process (DoS)
GHSA-j5f4-cc29-5x44highadm-zip@0.6.0adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation
GHSA-rcw4-f5rp-g42vhighadm-zip@0.6.0adm-zip: Decompression-bomb protection (fix for CVE-2026-39244) can be bypassed by declaring uncompressed size as 0
GHSA-3pq3-5fj3-cg6vhighaxios@1.18.1Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls
GHSA-542g-h47m-68v8highaxios@1.18.1Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization
GHSA-c29m-xwm3-cm6rhighaxios@1.18.1Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS)
GHSA-m8m8-qj5v-23w3highaxios@1.18.1Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection
GHSA-mghh-pgcx-3jjjhighaxios@1.18.1Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location
GHSA-r4gj-5m52-g5whhighaxios@1.18.1Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF
GHSA-x97p-jq2g-jp4fhighaxios@1.18.1Axios: Prototype Pollution Gadget in axios toFormData Options
GHSA-3jxr-9vmj-r5cphighbrace-expansion@1.1.15brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
GHSA-6j4f-fj2g-mc7phighbrace-expansion@1.1.15brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
Workflows worth a look

By the numbers

Stars9,956
Forks743
Contributors65
Commits1,216
Open issues77
Open pull requests1
Releases236
Latest releasev1.50.0
LicenceGPL-3.0
Main languageTypeScript
Project age1 year
Last pushOct 3, 2026
Tracked files1,808
Lines of code344.2K
Checkout size42 MB

Lines by language: TypeScript 289.6K, Markdown 24K, YAML 20.1K, JSON 5,353, JavaScript 3,276, CSS 969.

Questions

Is Read Frog free?

Yes. The extension is free in the Chrome, Edge and Firefox stores and the code is GPL-3.0, also available under a commercial licence for closed-source use. Google, Microsoft and DeepLX translation and Edge TTS voices cost nothing; AI providers bill you through your own API key, or nothing with a local Ollama model.

Which AI models does Read Frog support?

More than 20 providers through the Vercel AI SDK, including OpenAI, Anthropic Claude, Google Gemini, DeepSeek, xAI Grok, Groq, Mistral and Ollama, plus custom endpoints with your own model settings.

Can Read Frog translate YouTube videos?

It translates YouTube subtitles inside the player, showing the translation alongside the original captions. It does not dub audio; for videos without captions, there is nothing for it to translate.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.