Firefox Add-ons

RoC Wiki Goods

by Shiin · 23 users
000cce81-af58-5f8a-b71b-e71cc628fa94 | v1.3.0
31/ 100
LOW risk
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
4 months ago
Version
v1.3.0
Artifact
SHA256 D61…E0C
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

1 detail row

Publisher Evidence

Limited evidence

Shiin

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

34
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Limited signal
Limited
Extension portfolio
2
Portfolio

13 evidence rows available.

Finding Categories

1
Network

Requested Permissions

3 permissions
activeTab
Medium
storage
Low
*://*.riseofcultures.wiki.gg/*
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

This Firefox extension enhances the Rise of Cultures wiki with dropdown selectors, resource tracking checkboxes, and calculation tools for construction and upgrade tables. The automated security scanner flagged 129 medium-severity findings, but these are overwhelmingly false positives from known scanner limitations.

All 128 domain-related findings are property access chains misidentified as network destinations. For example, "XIOC-DOMAIN-t.actions.search" and "XIOC-DOMAIN-n.style.gap" are JavaScript property references like t.actions.search or n.style.gap, not actual domain names. Similarly, "XIOC-DOMAIN-g.to" and "XIOC-DOMAIN-r.compare" represent method chaining patterns in minified code. These patterns are documented false positives that occur when scanners cannot distinguish between legitimate object.property syntax and actual domain strings. Other flagged items like "XIOC-DOMAIN-r.gold", "XIOC-DOMAIN-t.food", and "XIOC-DOMAIN-nodefilter.show" follow the same pattern of property access chains.

The extension contains zero malware signatures, zero obfuscation indicators, and zero code-smell findings. This is significant because actual malicious extensions typically show at least one of these signals. The single network finding is consistent with a wiki enhancement tool that may need to fetch game data or wiki resources.

The extension's developer field is empty, which raises questions about accountability. However, this is common for small community-maintained tools targeting niche audiences. With only 25 users, this is clearly a specialized utility rather than a mass-market product. The description accurately describes a game wiki enhancement tool, and there is no evidence of browser hijacking, credential theft, or proxyware functionality.

Counterargument: A skeptic might argue that an anonymous developer with 129 flagged findings warrants caution. However, the nature of these findings matters more than the count. Every single flagged "domain" is a property access chain, not a real network destination. If this were malicious code, we would expect to see actual suspicious domains like custom search engines or data exfiltration endpoints, malware signatures, obfuscation, or code-smell findings. None of these are present. The findings are scanner noise, not evidence of harm.

Conclusion: This extension is a legitimate game wiki tool with automated scanner false positives. The findings should be suppressed as known false positive patterns.

Key Reasons

  • All 128 domain findings are property access chains (t.actions.search, n.style.gap, g.to) not real domains
  • Zero malware signatures detected
  • Zero obfuscation indicators present
  • Zero code-smell findings
  • Extension purpose matches description (game wiki enhancement tool)

False Positive Considerations

  • IoC extractor misreading property access chains as domains
  • No malware signatures present
  • No obfuscation or code-smell indicators
  • Legitimate extension purpose (game wiki enhancement)

Reviewed 2026-05-25; recommended action: suppress false positive; model confidence 85%.

About This Extension

This extension enhances your experience on the Rise of Cultures Wiki. Select building names using dropdown menus and save your choices directly in your browser. Placeholder text (primary/secondary/tertiary) is automatically replaced with game icons based on your selections, creating a more visual and intuitive interface. In the Technology table, the extension adds checkboxes to each row, making it easy to track required resources. A total row updates dynamically as you make selections, and a "Select All" button lets you quickly check all resources. In the Construction and Upgrade tables, plus (+) and minus (–) buttons let you easily increase or decrease the values for each row, helping you calculate totals for multiple buildings or upgrades. 🆕 <strong>Last Update:</strong> - Added new dropdown menu for the Early Gothic era. - Introduced a total row in the World Wonders tables. - Updated the popup error message for improved clarity and user understanding. <strong>Features:</strong> <ul><li>Dropdown menus to select Rise of Cultures buildings</li><li>Selections saved in your browser for easy reuse</li><li>Automatic replacement of placeholder text (primary/secondary/tertiary) with game icons</li><li>Checkboxes added to each row in the Technology table</li><li>Dynamic total row for selected technologies</li><li>"Select All" button for efficient tracking</li><li>Plus (+) and minus (–) buttons in Construction and Upgrade tables to multiply row values</li></ul> <strong>How to use:</strong> <ul><li>Choose building names from the dropdown menus in the extension popup</li><li>Reload the page to see updated icons</li><li>Use checkboxes in the Technology table to track your resources</li><li>View the total row for real-time progress</li><li>Adjust quantities in the Construction and Upgrade tables with the +/– buttons</li></ul> This extension streamlines resource management and makes the Wiki more interactive and user-friendly.

Frequently Asked Questions