Firefox Add-ons

Extension

by Hridya Agrawal · 23 users · 5.0 rating
000ff61e-3acd-56ed-b109-362cc4029287 | v4.2.0
53/ 100
MEDIUM risk
No change since v4.0.0
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (53/100) still counts them.

Analysis record

Analysed
5 months ago
Version
v4.2.0
Artifact
SHA256 D81…31E
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

70 detail rows
Showing 25 of 70 · highest severity first

Publisher Evidence

Limited evidence

Hridya Agrawal

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

34
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Limited signal
Limited
Extension portfolio
5
Portfolio

12 evidence rows available.

Finding Categories

69
Network

Requested Permissions

16 permissions
clipboardRead

Read data from your clipboard

High
tabs
Medium
storage
Low
clipboardWrite
Low
https://fonts.google.com/*
Low
https://fonts.googleapis.com/*
Low
https://fonts.gstatic.com/*
Low
https://emoji.slack-edge.com/*
Low
https://flavortown.hackclub.com/*
Low
https://shots.so/*
Low
https://cachet.dunkirk.sh/*
Low
https://gamblorpheus.hackclub.com/*
Low
https://ai.hackclub.com/*
Low
https://api.github.com/*
Low
https://raw.githubusercontent.com/*
Low
https://logpheus.gizzy.gay/*
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

This extension's 70 findings are concentrated entirely in the network category, with 69 findings titled NET-FETCH-[file]-[line] across content.js, background.js, and popup.js. Each finding description states only "Network call of type 'fetch' detected" without identifying any specific domain or endpoint. This pattern represents a known false positive: the CVEQ network detector flags any use of the fetch() API, which is standard JavaScript for making HTTP requests and is used by virtually all legitimate browser extensions.

Critically, the findings_summary shows 0 IoC findings, 0 malware-signature findings, 0 obfuscation findings, and 0 code-smell findings. The absence of IoC findings means no actual domain names were extracted as suspicious. The absence of malware signatures means no known malicious code patterns were detected. The absence of obfuscation means the code is not hidden or obfuscated. These are the findings that would indicate actual malicious behavior, and none are present.

The extension metadata shows concerning transparency gaps: the name field is empty, the developer_name field is empty, and only 37 users are recorded. The description references "Flavortown" which could indicate a gaming or community-focused utility. While anonymous publishing is a risk factor, it does not constitute evidence of malicious behavior when combined with clean code analysis.

The strongest counterargument to this verdict is that 69 network findings across multiple files suggests significant external communication that could exfiltrate data. However, without IoC findings showing actual destination domains, there is no evidence of where these requests go. Legitimate extensions routinely make dozens of fetch calls for API endpoints, content updates, and feature functionality. The detection of fetch() usage alone, without domain extraction or malware signatures, is insufficient to establish malicious intent. The evidence quality is moderate because while the network findings are numerous, they lack the specificity needed to identify actual threats.

Key Reasons

  • Zero IoC findings means no suspicious domains were identified
  • Zero malware signatures and zero obfuscation findings
  • Network findings are generic fetch() API detections, not specific domain calls
  • No code-smell findings despite 70 total detections

False Positive Considerations

  • Generic fetch() API detection without domain extraction
  • Network finding count inflation from legitimate HTTP requests

Reviewed 2026-04-27; recommended action: monitor; model confidence 82%.

Firefox version history

Risk trend by version

9 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
53
Change since first
-4
Change from previous
No change
Versions:
First analyzed version
2.0.0
Jan 24, 2026
Risk range
53 to 58
Across analyzed versions
Latest analyzed version
4.2.0
Apr 28, 2026
Selected version
medium
Version
v4.2.0
5 months ago
Risk score
53
Findings
70
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

Frequently Asked Questions