Literary Clock
Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 2 months ago
- Version
- v2.0.1
- Artifact
- SHA256 134…6E9
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidenceBora M. ALPER
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
Requested Permissions
4 permissionsAI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
Literary Clock is a Firefox extension with 21 users that displays literary quotes alongside earth imagery from satellite data. The extension has an empty developer name field, which is a red flag for anonymous publishing.
False Positive Findings:
The majority of the 28 IoC findings are documented false positives. The XIOC-IP-:: and XIOC-IP-8:: findings are IPv6 fragments that the CVEQ extractor commonly misidentifies from hex substrings in minified JavaScript. The XIOC-DOMAIN-mozilla.com, XIOC-DOMAIN-addons.mozilla.org, and XIOC-DOMAIN-signingca1.addons.mozilla.org findings reference Mozilla infrastructure, which is expected for Firefox extensions. The XIOC-URL-https://www.data.jma.go.jp/mscweb/data/himawari/sat_img.php?area=fd_ is a legitimate URL from the Japan Meteorological Agency for Himawari satellite imagery, which directly supports the extension's described functionality of showing earth imagery. The XIOC-DOMAIN-res.author and XIOC-DOMAIN-res.work findings are property access chains (e.g., res.author) misread as domains by the extractor.
Suspicious Signals:
Two domains stand out: herself.it and boramalper.org from the XIOC-DOMAIN-herself.it and XIOC-URL-http://boramalper.org findings. These are not Mozilla, Google, or CDN infrastructure domains. The XIOC-DOMAIN-earth.data finding uses an unusual TLD but could relate to the extension's earth imagery feature. The 12 code-smell findings are all low severity and match benign patterns in the findings_summary.
Counterargument:
A skeptic would argue that herself.it and boramalper.org represent actual data exfiltration endpoints, especially given the empty developer name and unusual version string "1.3.2resigned1". However, there are zero malware signatures, zero obfuscation findings, and no evidence of credential theft, browser hijacking, or proxyware behavior. The extension's functionality (satellite imagery + quotes) is coherent and the JMA URL confirms legitimate data sources. Without malware signatures co-located with obfuscation, or evidence of credential/session theft, these domains alone do not confirm malicious intent.
Conclusion: The finding volume is driven by known false positive patterns. The two suspicious domains warrant monitoring but lack corroborating evidence of malicious behavior.
Key Reasons
- Most IoCs are known false positives (IPv6 fragments, Mozilla domains, property access chains)
- Zero malware signatures or obfuscation findings
- Legitimate JMA satellite URL matches extension description
- Two non-infrastructure domains (herself.it, boramalper.org) lack corroborating malicious evidence
- Anonymous publisher is concerning but not determinative
False Positive Considerations
- IPv6 fragments (::, 8::) from minified JS
- Mozilla infrastructure domains (addons.mozilla.org, mozilla.com)
- Property access chains misread as domains (res.author, res.work)
- Low-severity code-smell findings
Reviewed 2026-04-28; recommended action: suppress false positive; model confidence 72%.
Firefox version history
Risk trend by version
3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Search Shortcut
Bora M. ALPER
VaultysHub extension
Vaultys
Kindredly - A safer, private web for families
Kindredly.ai
Malwarebytes Browser Guard
Malwarebytes
VHS - Dev Tools
Vihat Software
Ultimate New Tab Page - AI Search & Dial
Dracon