Firefox Add-ons

Duolingo Fast Mode

by Freinorg · 61 users
0000095c-23bf-5084-9965-1aa7da5f6815 | v1.5.3
36/ 100
LOW risk
-4 since v1.5.0
Risk verdict
No high-risk signal observed

Score-based assessment (low risk, 36/100). Last analyst review covers version 1.5.0.

Analysis record

Analysed
1 months ago
Version
v1.5.3
Artifact
SHA256 FCD…4B2
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

7 detail rows

YARA Rule Matches

6 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall file manipulation 1
assets/scripts/content.js
-
LOWpostinstall obfuscation 1
assets/scripts/injected.js
-
LOWpostinstall network communication 2
assets/scripts/content.jsassets/scripts/popup.js
-
LOWpostinstall system command 1
assets/scripts/content.js
-
LOWpostinstall file download 1
assets/scripts/injected.js
-
LOWLocalStorageShouldNotBeUsed 1
assets/scripts/content.js
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

13 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

Freinorg

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

29
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Limited signal
Limited
Extension portfolio
2
Portfolio

12 evidence rows available.

Finding Categories

13
IoC Indicators

YARA Rules Matched

6 rules(7 hits)
postinstall file manipulation postinstall obfuscation postinstall network communication postinstall system command postinstall file download LocalStorageShouldNotBeUsed

Requested Permissions

3 permissions
storage
Low
unlimitedStorage
Low
https://www.duolingo.com/*
Low

AI Security Report

AI Security Review

Evidence context: threat category typosquatting; evidence quality weak.

The "Duolingo Fast Mode" extension presents an ambiguous security posture requiring further investigation. The extension's name explicitly references Duolingo, a well-known language learning platform, without any developer attribution linking it to Duolingo's official organization. This naming pattern aligns with common typosquatting tactics where third-party extensions attempt to associate with popular services to gain user trust.

The developer field is completely empty (developer_name: ""), indicating an anonymous publisher. Combined with the Duolingo-branded name, this creates a concerning profile: users cannot verify who is behind the extension or what data practices it follows. The extension claims to provide "hints" to help users "save time and stress less" (description field), but without code analysis findings, the actual functionality remains unknown.

Critically, this evidence bundle contains zero findings across all security categories—no IoCs, no code-smell detections, no obfuscation patterns, and no malware signatures (findings_by_category: {}). While this absence could indicate a genuinely clean extension, it is highly unusual for any non-trivial browser extension. Even legitimate extensions typically trigger some code-smell rules (such as network request patterns, storage access, or DOM manipulation) or contain benign IoCs (such as CDN domains or analytics endpoints). The complete absence of findings suggests either an exceptionally minimal extension or an incomplete analysis run.

Strongest Counterargument:

A skeptic might argue that zero findings definitively proves this extension is safe. However, this reasoning ignores the suspicious naming pattern and anonymous publisher. The Duolingo association without official attribution is a known risk pattern for extensions that inject ads, harvest user data, or provide fake premium features. Without behavioral evidence, we cannot confirm malicious intent, but we also cannot rule it out. The combination of typosquatting-style naming, anonymous publishing, and unusually clean findings warrants runtime analysis or manual review to determine actual functionality.

Recommendation:

This extension requires follow-up investigation. Runtime analysis would reveal whether it communicates with suspicious domains, modifies Duolingo's behavior, or exfiltrates user data. Until then, users should exercise caution with this extension despite the lack of automated findings.

Key Reasons

  • Extension name references Duolingo without developer attribution
  • Anonymous publisher (empty developer_name field)
  • Zero findings across all security categories is unusual
  • Low user count (31) limits behavioral data

Reviewed 2026-04-22; recommended action: runtime analysis; model confidence 65%.

Firefox version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
36
Change since first
-4
Change from previous
-4
Versions:
First analyzed version
1.5.0
Apr 4, 2026
Risk range
36 to 40
Across analyzed versions
Latest analyzed version
1.5.3
Aug 12, 2026
Selected version
low
Version
v1.5.3
1 months ago
Risk score
36
Findings
20
Change vs previous
-4

Pick any point on the chart to explore that version's code below.

About This Extension

Features <ul><li>Provides immediate feedback on correctness</li><li>Auto complete using buttons or hotkeys</li><li>Indicates when the task is safe to check</li><li>Supports all non speaking challeng</li></ul>

Frequently Asked Questions