Microsoft Edge Add-ons Verified

PC Protect Password Vault Assistant

0015b626-f25b-5efd-be54-1de2d7ab55ad | v1.4.66
53/ 100
MEDIUM risk
Risk verdict
Review before use

Score-based assessment (medium risk, 53/100). Last analyst review covers version unknown.

Analysis record

Analysed
6 months ago
Version
v1.4.66
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

35 detail rows

YARA Rule Matches

7 rules
SeverityRuleHitsFilesMetadata
HIGHpostinstall crypto operations

Cryptographic operations detected

2
shared/js/jquery-3.5.0.js_metadata/verified_contents.json
Risky Plugins Authors FP 30%
HIGHNoUseWeakRandom

When software generates predictable values in a context requiring unpredictability, it may be possible for an attacker to guess the next value that will be generated, and use this guess to impersonate another user or access sensitive information. As the Math.random() function relies on a weak pseudorandom number generator, this function should not be used for security-critical applications or for protecting sensitive data. In such context, a cryptographically strong pseudorandom number generator (CSPRNG) should be used instead. For more information checkout the CWE-338 (https://cwe.mitre.org/data/definitions/338.html) advisory.

2
shared/js/jquery-3.5.0.jsshared/js/content-script.js
FP 5%
HIGHpostinstall network communication

Network communication detected

3
shared/js/jquery-3.5.0.jsshared/js/service-worker.jsshared/js/content-script.js
Risky Plugins Authors FP 30%
HIGHpostinstall file manipulation

File system manipulation detected

2
shared/js/jquery-3.5.0.jsshared/js/content-script.js
Risky Plugins Authors FP 20%
HIGHpostinstall system command

System command execution detected

1
shared/js/jquery-3.5.0.js
Risky Plugins Authors FP 10%
HIGHpostinstall obfuscation

Code obfuscation techniques detected

2
shared/js/jquery-3.5.0.jsshared/js/content-script.js
Risky Plugins Authors FP 20%
HIGHSQLInjection

SQL queries often need to use a hardcoded SQL string with a dynamic parameter coming from a user request. Formatting a string to add those parameters to the request is a bad practice as it can result in an SQL injection. The safe way to add parameters to a SQL query is to use SQL binding mechanisms. For more information checkout the CWE-564 (https://cwe.mitre.org/data/definitions/564.html) and OWASP A1:2017 (https://owasp.org/www-project-top-ten/2017/A1_2017-Injection.html) advisory.

1
shared/js/jquery-3.5.0.js
FP 10%

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

125 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

PC Protect

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

42
Noisy-finding weight
x1.00
Publisher domain
pcprotect.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
4
Portfolio

12 evidence rows available.

Finding Categories

13
Malware Signatures
1
Network
125
IoC Indicators

YARA Rules Matched

7 rules(13 hits)
postinstall crypto operations NoUseWeakRandom postinstall network communication postinstall file manipulation postinstall system command postinstall obfuscation SQLInjection

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

This extension appears to be a legitimate password management component associated with the PC Protect antivirus suite. It explicitly claims functionality to access and generate passwords via the 'Password Vault', which requires standard credential API access (permissions often flagged as 'high-risk' by automated scanners).

The triage is based on the complete absence of suspicious findings (zero malware signatures, zero IoCs, and zero code-smell detections). While the user count is reported as zero (often an artifact for offline or pre-installed security tools in enterprise environments), the publisher identity ('PC Protect') is clearly attributed, distinguishing this from anonymous or impersonating malware.

Password managers inherently access sensitive data to function correctly; however, this specific analysis shows no evidence of external data transmission, browser hijacking, or obfuscation commonly seen in credential theft variants. The findings are consistent with a benign utility from a known security vendor.

Key Reasons

  • Zero findings across all detection categories (Malware, IoCs, Code-smell).
  • Attributed developer 'PC Protect' matches the extension branding.
  • Functionality (password generation/retrieval) explains permissions without malicious indicators.

False Positive Considerations

  • High-risk permissions (credentials) are inherent functionality for password managers.
  • Zero user count likely reflects an offline/internal deployment status rather than malware stealth.
  • Publisher is clearly attributed (PC Protect), ruling out typosquatting.

Reviewed 2026-04-13; recommended action: no action; model confidence 90%.

Frequently Asked Questions