Duolingo Fast Mode
Score-based assessment (low risk, 36/100). Last analyst review covers version 1.5.0.
Analysis record
- Analysed
- 1 months ago
- Version
- v1.5.3
- Artifact
- SHA256 FCD…4B2
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
6 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall file manipulation | 1 | assets/scripts/content.js | - |
| LOW | postinstall obfuscation | 1 | assets/scripts/injected.js | - |
| LOW | postinstall network communication | 2 | assets/scripts/content.jsassets/scripts/popup.js | - |
| LOW | postinstall system command | 1 | assets/scripts/content.js | - |
| LOW | postinstall file download | 1 | assets/scripts/injected.js | - |
| LOW | LocalStorageShouldNotBeUsed | 1 | assets/scripts/content.js | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidenceFreinorg
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
YARA Rules Matched
6 rules(7 hits)Requested Permissions
3 permissionsAI Security Report
AI Security Review
Evidence context: threat category typosquatting; evidence quality weak.
The "Duolingo Fast Mode" extension presents an ambiguous security posture requiring further investigation. The extension's name explicitly references Duolingo, a well-known language learning platform, without any developer attribution linking it to Duolingo's official organization. This naming pattern aligns with common typosquatting tactics where third-party extensions attempt to associate with popular services to gain user trust.
The developer field is completely empty (developer_name: ""), indicating an anonymous publisher. Combined with the Duolingo-branded name, this creates a concerning profile: users cannot verify who is behind the extension or what data practices it follows. The extension claims to provide "hints" to help users "save time and stress less" (description field), but without code analysis findings, the actual functionality remains unknown.
Critically, this evidence bundle contains zero findings across all security categories—no IoCs, no code-smell detections, no obfuscation patterns, and no malware signatures (findings_by_category: {}). While this absence could indicate a genuinely clean extension, it is highly unusual for any non-trivial browser extension. Even legitimate extensions typically trigger some code-smell rules (such as network request patterns, storage access, or DOM manipulation) or contain benign IoCs (such as CDN domains or analytics endpoints). The complete absence of findings suggests either an exceptionally minimal extension or an incomplete analysis run.
Strongest Counterargument:
A skeptic might argue that zero findings definitively proves this extension is safe. However, this reasoning ignores the suspicious naming pattern and anonymous publisher. The Duolingo association without official attribution is a known risk pattern for extensions that inject ads, harvest user data, or provide fake premium features. Without behavioral evidence, we cannot confirm malicious intent, but we also cannot rule it out. The combination of typosquatting-style naming, anonymous publishing, and unusually clean findings warrants runtime analysis or manual review to determine actual functionality.
Recommendation:
This extension requires follow-up investigation. Runtime analysis would reveal whether it communicates with suspicious domains, modifies Duolingo's behavior, or exfiltrates user data. Until then, users should exercise caution with this extension despite the lack of automated findings.
Key Reasons
- Extension name references Duolingo without developer attribution
- Anonymous publisher (empty developer_name field)
- Zero findings across all security categories is unusual
- Low user count (31) limits behavioral data
Reviewed 2026-04-22; recommended action: runtime analysis; model confidence 65%.
Firefox version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
SelectMind AI
Freinorg
VaultysHub extension
Vaultys
Kindredly - A safer, private web for families
Kindredly.ai
Malwarebytes Browser Guard
Malwarebytes
VHS - Dev Tools
Vihat Software
Ultimate New Tab Page - AI Search & Dial
Dracon