WCAG Color contrast checker
From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 6 months ago
- Version
- v3.8.5
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
5 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | postinstall network communication Network communication detected | 2 | content_scripts/contrastChecker.jsservice-worker.js | Risky Plugins Authors FP 30% |
| HIGH | postinstall file manipulation File system manipulation detected | 2 | content_scripts/contrastChecker.jsservice-worker.js | Risky Plugins Authors FP 20% |
| HIGH | postinstall system command System command execution detected | 4 | html/releaseNotes.htmlcontent_scripts/contrastChecker.jsservice-worker.js +1 more | Risky Plugins Authors FP 10% |
| HIGH | postinstall obfuscation Code obfuscation techniques detected | 3 | html/releaseNotes.htmlcontent_scripts/contrastChecker.jshtml/help.html | Risky Plugins Authors FP 20% |
| HIGH | postinstall crypto operations Cryptographic operations detected | 1 | _metadata/verified_contents.json | Risky Plugins Authors FP 30% |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidenceRumoroso
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
YARA Rules Matched
5 rules(12 hits)AI Security Report
AI Security Review
Evidence context: threat category unknown malware; evidence quality weak.
The WCAG Color contrast checker extension by developer 'Rumoroso' presents an ambiguous security picture. The extension's stated purpose—checking color contrast between foreground and background text—is a legitimate accessibility function.
All 31 IoC findings are known false-positive patterns. The domain chrome.storage is a Chrome API reference, not a network domain. Property access chains like e.id, l.space, tab.id, menu-item.menu, menu-trigger.menu, and t.target are JavaScript object property accesses misread as domains. The IPv6 fragment e::f is a hex substring from minified code, not a real IP. The domains www.gimp.org and purl.org are legitimate websites (GIMP image editor and Persistent Uniform Resource Locator service). These IoC patterns match documented CVEQ false-positive noise sources.
However, 12 malware-signature findings at high severity require investigation. Without specific signature names or malware family identifiers in the evidence, I cannot determine if these are legitimate threat detections or broad YARA rules matching common code patterns. The absence of actual malware category findings (0) alongside malware-signature findings (12) suggests these may be signature matches that don't meet the threshold for confirmed malware classification.
The version being 'unknown' is a critical data gap that prevents proper analysis. Combined with 0 users, this extension lacks community validation. The developer 'Rumoroso' is not a known publisher, providing no trust signal.
Counterargument: A skeptic could argue the 12 high-severity malware-signature findings alone warrant a confirmed_malicious verdict. However, malware-signature findings without specific family names, combined with zero actual malware detections and exclusively false-positive IoCs, creates genuine ambiguity. The extension's legitimate accessibility purpose further complicates the assessment. Without knowing which specific signatures triggered, or seeing obfuscation/credential theft/network findings that would confirm malicious intent, a definitive malicious verdict is premature.
Runtime analysis or reanalysis with version information is needed to determine if the malware-signature findings represent actual threats or detection noise.
Key Reasons
- 12 malware-signature findings without specific family names
- All 31 IoCs are documented false-positive patterns
- Version unknown prevents proper analysis
- Legitimate accessibility extension purpose
- No obfuscation, credential theft, or network findings
False Positive Considerations
- IoC property access chains misread as domains
- IPv6 fragment hex substrings
- Legitimate domain references (gimp.org, purl.org)
- Chrome API references (chrome.storage)
Reviewed 2026-04-27; recommended action: runtime analysis; model confidence 62%.
Source Code Not Available
Source code is not available for this version of the extension.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace