Microsoft Edge Add-ons Verified

React Developer Tools

00bd84e4-a1eb-5a63-9f47-c271e36fe03e | v8.0.0
38/ 100
LOW risk
-8 since v7.0.1 (10/20/2025)
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
3 weeks ago
Version
v8.0.0
Artifact
SHA256 241…5BF
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

20 detail rows

Publisher Evidence

Limited evidence

Meta Platforms, Inc.

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

28
Noisy-finding weight
x1.00
Publisher domain
react.dev
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

1
Network

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

This extension is React Developer Tools, a well-known debugging tool published by Meta Platforms, Inc., the creators of the React framework. The extension's stated purpose in manifest.json is to add React debugging tools to Microsoft Edge Developer Tools, which aligns with its legitimate function.

The evidence shows 63 malware-signature findings categorized as high severity, but critically, these findings are not detailed in the findings_by_category section. This pattern is characteristic of CVEQ's known false positive behavior where bundled dependencies or minified JavaScript trigger broad YARA rules. The extension contains no IoC findings (0 suspicious domains), no obfuscation findings, no code-smell findings, and no secret findings - all of which would be expected if this were actual malware.

The single network finding (NET-FETCH-build/fileFetcher.js-1) shows a fetch call in build/fileFetcher.js, which is normal behavior for any extension that needs to load resources or communicate with content scripts. This is not evidence of data exfiltration or malicious communication.

The 11 metadata findings are simply file hashes for legitimate files like popups/unminified.html, icons/production.svg, and manifest.json. These are informational findings that do not indicate any security concern.

Counterargument: A skeptic might argue that 63 high-severity malware-signature findings should warrant concern regardless of publisher identity. However, this reasoning ignores the documented CVEQ false positive patterns: malware-signature rules frequently fire on bundled npm packages, minified React code, and legitimate debugging tool functionality. The absence of any specific suspicious domains, credential access patterns, or obfuscation techniques - combined with the verified Meta publisher identity - confirms these are false positives. If this were actual malware, we would expect to see at least one specific malicious domain in the IoC findings, which is absent here.

The extension's user count of 0 is likely due to this being a newly analyzed version or test data, not an indicator of risk. React Developer Tools is one of the most widely used developer extensions globally.

Key Reasons

  • Verified publisher (Meta Platforms, Inc.) with legitimate extension purpose
  • Zero IoC findings - no suspicious domains detected
  • Zero obfuscation findings despite 63 malware-signature alerts
  • Single network finding is normal fetch behavior in fileFetcher.js
  • Malware-signature findings not detailed in evidence - consistent with bundled code FP pattern

False Positive Considerations

  • Bundled dependencies triggering YARA rules
  • Minified React code matching broad malware-signature patterns
  • CVEQ scoring inflation from finding count rather than finding nature
  • No specific malicious domains in IoC findings

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.

Edge version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
38
Change since first
-8
Change from previous
-8
Versions:
First analyzed version
7.0.1 (10/20/2025)
Apr 4, 2026
Risk range
38 to 46
Across analyzed versions
Latest analyzed version
8.0.0
Sep 10, 2026
Selected version
low
Version
v8.0.0
3 weeks ago
Risk score
38
Findings
20
Change vs previous
-8

Pick any point on the chart to explore that version's code below.

Frequently Asked Questions