Microsoft Edge Add-ons

WCAG Color contrast checker

00c1c7cb-6fa3-538a-986d-7af021a6aa41 | v3.8.5
43/ 100
MEDIUM risk
Analyst verdict
Needs follow up

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
6 months ago
Version
v3.8.5
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

33 detail rows

YARA Rule Matches

5 rules
SeverityRuleHitsFilesMetadata
HIGHpostinstall network communication

Network communication detected

2
content_scripts/contrastChecker.jsservice-worker.js
Risky Plugins Authors FP 30%
HIGHpostinstall file manipulation

File system manipulation detected

2
content_scripts/contrastChecker.jsservice-worker.js
Risky Plugins Authors FP 20%
HIGHpostinstall system command

System command execution detected

4
html/releaseNotes.htmlcontent_scripts/contrastChecker.jsservice-worker.js +1 more
Risky Plugins Authors FP 10%
HIGHpostinstall obfuscation

Code obfuscation techniques detected

3
html/releaseNotes.htmlcontent_scripts/contrastChecker.jshtml/help.html
Risky Plugins Authors FP 20%
HIGHpostinstall crypto operations

Cryptographic operations detected

1
_metadata/verified_contents.json
Risky Plugins Authors FP 30%

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

21 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

Rumoroso

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

39
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Limited signal
Limited
Extension portfolio
6
Portfolio

12 evidence rows available.

Finding Categories

12
Malware Signatures
21
IoC Indicators

YARA Rules Matched

5 rules(12 hits)
postinstall network communication postinstall file manipulation postinstall system command postinstall obfuscation postinstall crypto operations

AI Security Report

AI Security Review

Evidence context: threat category unknown malware; evidence quality weak.

The WCAG Color contrast checker extension by developer 'Rumoroso' presents an ambiguous security picture. The extension's stated purpose—checking color contrast between foreground and background text—is a legitimate accessibility function.

All 31 IoC findings are known false-positive patterns. The domain chrome.storage is a Chrome API reference, not a network domain. Property access chains like e.id, l.space, tab.id, menu-item.menu, menu-trigger.menu, and t.target are JavaScript object property accesses misread as domains. The IPv6 fragment e::f is a hex substring from minified code, not a real IP. The domains www.gimp.org and purl.org are legitimate websites (GIMP image editor and Persistent Uniform Resource Locator service). These IoC patterns match documented CVEQ false-positive noise sources.

However, 12 malware-signature findings at high severity require investigation. Without specific signature names or malware family identifiers in the evidence, I cannot determine if these are legitimate threat detections or broad YARA rules matching common code patterns. The absence of actual malware category findings (0) alongside malware-signature findings (12) suggests these may be signature matches that don't meet the threshold for confirmed malware classification.

The version being 'unknown' is a critical data gap that prevents proper analysis. Combined with 0 users, this extension lacks community validation. The developer 'Rumoroso' is not a known publisher, providing no trust signal.

Counterargument: A skeptic could argue the 12 high-severity malware-signature findings alone warrant a confirmed_malicious verdict. However, malware-signature findings without specific family names, combined with zero actual malware detections and exclusively false-positive IoCs, creates genuine ambiguity. The extension's legitimate accessibility purpose further complicates the assessment. Without knowing which specific signatures triggered, or seeing obfuscation/credential theft/network findings that would confirm malicious intent, a definitive malicious verdict is premature.

Runtime analysis or reanalysis with version information is needed to determine if the malware-signature findings represent actual threats or detection noise.

Key Reasons

  • 12 malware-signature findings without specific family names
  • All 31 IoCs are documented false-positive patterns
  • Version unknown prevents proper analysis
  • Legitimate accessibility extension purpose
  • No obfuscation, credential theft, or network findings

False Positive Considerations

  • IoC property access chains misread as domains
  • IPv6 fragment hex substrings
  • Legitimate domain references (gimp.org, purl.org)
  • Chrome API references (chrome.storage)

Reviewed 2026-04-27; recommended action: runtime analysis; model confidence 62%.

Frequently Asked Questions