Is "Sourcegraph for Firefox" on Firefox Add-ons Safe to Install?

Sourcegraph · firefox · v23.4.14.1343

The open-source Sourcegraph extension adds code navigation and code intelligence to GitHub, GitHub Enterprise, GitLab, Bitbucket Server, and Phabricator. • Code intelligence on your code host: * Hover tooltips with documentation and type information * Go to definition * Find references • Integrations with third-party services like Codecov coverage overlays, open-in-editor buttons and many more with Sourcegraph extensions • Browser shortcut (src + Space) that performs the search on your Sourcegraph instance It works for 20+ languages on public and private code on popular code hosts (see below). Make it work on your code host: • GitHub - No action required. Your extension works here by default. • GitHub Enterprise, GitLab, Bitbucket Server and Phabricator - grant additional permissions in the extension menu Browser extension docs: https://docs.sourcegraph.com/integration/browser_extension Make it work for private code: To use the browser extension with your private repositories, you need to set up a private Sourcegraph instance and connect it to the extension. Installation docs: https://docs.sourcegraph.com/admin/install Where to start? After adding the extension you install it, try it out on any of these public repositories: • Go: https://github.com/gorilla/mux/blob/9e1f59/mux.go or https://github.com/dgrijalva/jwt-go/pull/152/files#diff-f615844d3497ff38db57e459d6ef657bL48 • Java: https://github.com/google/guava/blob/581ba1/guava/src/com/google/common/collect/ImmutableList.java • TypeScript: https://github.com/angular/angular/blob/a2878b/packages/benchpress/src/reporter/console_reporter.ts or https://github.com/sindresorhus/got/pull/917/files#diff-02301bc46e8b878f10e9a8339efb7de7R176 • C#: https://github.com/paiden/Nett/pull/76/files#diff-e969e1315b2cb01bab80b2860be0d87eR52 • Python: https://github.com/ageitgey/face_recognition/blob/b8fed6/examples/facerec_on_raspberry_pi.py This extension is open source: https://github.com/sourcegraph/sourcegraph/tree/master/browser

Risk Assessment

Analyzed
54.22
out of 100
MEDIUM

1495 security findings detected across all analyzers

Firefox extension requesting 9 permissions

Severity Breakdown

0
Critical
672
High
823
Medium
0
Low
0
Info

Finding Categories

672
Malware Signatures
328
IoC Indicators

YARA Rules Matched

14 rules(672 hits)
postinstall file manipulation postinstall system command postinstall network communication postinstall obfuscation postinstall crypto operations NoUseWeakRandom postinstall environment access credential env files postinstall persistence mechanism postinstall registry modification postinstall file download LocalStorageShouldNotBeUsed SQLInjection DebuggerStatementsShouldNotBeUsed

Requested Permissions

9 permissions
<all_urls>

Access and modify data on every website you visit

Dangerous
http://*/*
Dangerous
https://*/*
Dangerous
activeTab
Medium
tabs
Medium
storage
Low
contextMenus
Low
https://github.com/*
Low
https://sourcegraph.com/*
Low

About This Extension

The open-source Sourcegraph extension adds code navigation and code intelligence to GitHub, GitHub Enterprise, GitLab, Bitbucket Server, and Phabricator. • Code intelligence on your code host: * Hover tooltips with documentation and type information * Go to definition * Find references • Integrations with third-party services like Codecov coverage overlays, open-in-editor buttons and many more with Sourcegraph extensions • Browser shortcut (src + Space) that performs the search on your Sourcegraph instance It works for 20+ languages on public and private code on popular code hosts (see below). <strong>Make it work on your code host:</strong> • GitHub - No action required. Your extension works here by default. • GitHub Enterprise, GitLab, Bitbucket Server and Phabricator - grant additional permissions in the extension menu Browser extension docs: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/e8c426ee279e08f2ac84eceafb293817b2dfa7df0ec26fdd9598c2a1a5505d21/https%3A//docs.sourcegraph.com/integration/browser_extension" rel="nofollow">https://docs.sourcegraph.com/integration/browser_extension</a> <strong>Make it work for private code:</strong> To use the browser extension with your private repositories, you need to set up a private Sourcegraph instance and connect it to the extension. Installation docs: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/ee1ff40714c6b3f844fdcd86938b5f63abacd0d6569004627be056cbc22f4f45/https%3A//docs.sourcegraph.com/admin/install" rel="nofollow">https://docs.sourcegraph.com/admin/install</a> <strong>Where to start?</strong> After adding the extension you install it, try it out on any of these public repositories: • Go: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/fea14027259b058fa9c05268eb4d8a78d04357700edb62f1c62805c2c5163701/https%3A//github.com/gorilla/mux/blob/9e1f59/mux.go" rel="nofollow">https://github.com/gorilla/mux/blob/9e1f59/mux.go</a> or <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/848ec07df78de6f3c080086827d67ffc0c4d94b6d3f14131abae0f2699ceef94/https%3A//github.com/dgrijalva/jwt-go/pull/152/files%23diff-f615844d3497ff38db57e459d6ef657bL48" rel="nofollow">https://github.com/dgrijalva/jwt-go/pull/152/files#diff-f615844d3497ff38db57e459d6ef657bL48</a> • Java: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/a07300d4cc8c85b825913ed89a09897f2242b76a42917bf327a820dabc38c67f/https%3A//github.com/google/guava/blob/581ba1/guava/src/com/google/common/collect/ImmutableList.java" rel="nofollow">https://github.com/google/guava/blob/581ba1/guava/src/com/google/common/collect/ImmutableList.java</a> • TypeScript: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/02689d907172b86d44d5173e38cae551b771e874ef67bf0472c84b0bb3abd612/https%3A//github.com/angular/angular/blob/a2878b/packages/benchpress/src/reporter/console_reporter.ts" rel="nofollow">https://github.com/angular/angular/blob/a2878b/packages/benchpress/src/reporter/console_reporter.ts</a> or <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/f1c4a5e821d1c03f5bf5c41df02aaa8c76a9a7ccf4f6b124f11acc09a28809db/https%3A//github.com/sindresorhus/got/pull/917/files%23diff-02301bc46e8b878f10e9a8339efb7de7R176" rel="nofollow">https://github.com/sindresorhus/got/pull/917/files#diff-02301bc46e8b878f10e9a8339efb7de7R176</a> • C#: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/8e5bce1d49862dada012e41fdca8060f3348274da597ae9c9039faa2a7d7908f/https%3A//github.com/paiden/Nett/pull/76/files%23diff-e969e1315b2cb01bab80b2860be0d87eR52" rel="nofollow">https://github.com/paiden/Nett/pull/76/files#diff-e969e1315b2cb01bab80b2860be0d87eR52</a> • Python: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/d924dc217f7b4eea72488c3eeaa90b2fd2813d43fcf60301b2644cf5f4224cce/https%3A//github.com/ageitgey/face_recognition/blob/b8fed6/examples/facerec_on_raspberry_pi.py" rel="nofollow">https://github.com/ageitgey/face_recognition/blob/b8fed6/examples/facerec_on_raspberry_pi.py</a> This extension is open source: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/b03e0b24231ff2b968d8beb3aa6305d85ca982d60e47617cba30db04da02a4dc/https%3A//github.com/sourcegraph/sourcegraph/tree/master/browser" rel="nofollow">https://github.com/sourcegraph/sourcegraph/tree/master/browser</a>

Detailed Findings

672 total

YARA Rule Matches

14 rules

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

URLs
3
Domains
325
Strings
328

All Indicators · 328

URL
detected URL: https://sourcegraph.example.com

XIOC detected URL: https://sourcegraph.example.com

extracted_from_files

Domain
detected Domain: is.name

XIOC detected Domain: is.name

extracted_from_files

Domain
detected Domain: seq.int

XIOC detected Domain: seq.int

extracted_from_files

Domain
detected Domain: s.search

XIOC detected Domain: s.search

extracted_from_files

Domain
detected Domain: this.regexes.map

XIOC detected Domain: this.regexes.map

extracted_from_files

Domain
detected Domain: r.contains.map

XIOC detected Domain: r.contains.map

extracted_from_files

Domain
detected Domain: e.variants.map

XIOC detected Domain: e.variants.map

extracted_from_files

Domain
detected Domain: map.call

XIOC detected Domain: map.call

extracted_from_files

Domain
detected Domain: o.map

XIOC detected Domain: o.map

extracted_from_files

Domain
detected Domain: e.re

XIOC detected Domain: e.re

extracted_from_files

Domain
detected Domain: month.abb

XIOC detected Domain: month.abb

extracted_from_files

Domain
detected Domain: t.safe

XIOC detected Domain: t.safe

extracted_from_files

Domain
detected Domain: t.in

XIOC detected Domain: t.in

extracted_from_files

Domain
detected Domain: is.na

XIOC detected Domain: is.na

extracted_from_files

Domain
detected Domain: u.show

XIOC detected Domain: u.show

extracted_from_files

Domain
detected Domain: de.call

XIOC detected Domain: de.call

extracted_from_files

Domain
detected Domain: he.call

XIOC detected Domain: he.call

extracted_from_files

Domain
detected Domain: t.ownerdocument.doctype.name

XIOC detected Domain: t.ownerdocument.doctype.name

extracted_from_files

Domain
detected Domain: t.context.next

XIOC detected Domain: t.context.next

extracted_from_files

Domain
detected Domain: marked.js.org

XIOC detected Domain: marked.js.org

extracted_from_files

Domain
detected Domain: gitlab.com

XIOC detected Domain: gitlab.com

extracted_from_files

Domain
detected Domain: a.now

XIOC detected Domain: a.now

extracted_from_files

Domain
detected Domain: s.global

XIOC detected Domain: s.global

extracted_from_files

Domain
detected Domain: l.host

XIOC detected Domain: l.host

extracted_from_files

Domain
detected Domain: fe.call

XIOC detected Domain: fe.call

extracted_from_files

Domain
detected Domain: e.roots.next

XIOC detected Domain: e.roots.next

extracted_from_files

Domain
detected Domain: e.template.parts

XIOC detected Domain: e.template.parts

extracted_from_files

Domain
detected Domain: i.search

XIOC detected Domain: i.search

extracted_from_files

Domain
detected Domain: as.call

XIOC detected Domain: as.call

extracted_from_files

Domain
detected Domain: month.name

XIOC detected Domain: month.name

extracted_from_files

Domain
detected Domain: da.next

XIOC detected Domain: da.next

extracted_from_files

Domain
detected Domain: wo.next

XIOC detected Domain: wo.next

extracted_from_files

Domain
detected Domain: y.data

XIOC detected Domain: y.data

extracted_from_files

Domain
detected Domain: r.off

XIOC detected Domain: r.off

extracted_from_files

Domain
detected Domain: p.prototype.run

XIOC detected Domain: p.prototype.run

extracted_from_files

Domain
detected Domain: o.keys.ie

XIOC detected Domain: o.keys.ie

extracted_from_files

Domain
detected Domain: e.dvr

XIOC detected Domain: e.dvr

extracted_from_files

Domain
detected Domain: k.now

XIOC detected Domain: k.now

extracted_from_files

Domain
detected Domain: r.args.map

XIOC detected Domain: r.args.map

extracted_from_files

Domain
detected Domain: ke.now

XIOC detected Domain: ke.now

extracted_from_files

Domain
detected Domain: e-t.now

XIOC detected Domain: e-t.now

extracted_from_files

Domain
detected Domain: pa.next

XIOC detected Domain: pa.next

extracted_from_files

Domain
detected Domain: o.style

XIOC detected Domain: o.style

extracted_from_files

Domain
detected Domain: e.help

XIOC detected Domain: e.help

extracted_from_files

Domain
detected Domain: e.play

XIOC detected Domain: e.play

extracted_from_files

Domain
detected Domain: e.camera

XIOC detected Domain: e.camera

extracted_from_files

Domain
detected Domain: e.tv

XIOC detected Domain: e.tv

extracted_from_files

Domain
detected Domain: e.rootchanges.next

XIOC detected Domain: e.rootchanges.next

extracted_from_files

URL
detected URL: http://www.w3.org/1999/xhtml

XIOC detected URL: http://www.w3.org/1999/xhtml

extracted_from_files

Domain
detected Domain: e.searchcontextchanges.next

XIOC detected Domain: e.searchcontextchanges.next

extracted_from_files

Domain
detected Domain: e.activeviewcomponentchanges.next

XIOC detected Domain: e.activeviewcomponentchanges.next

extracted_from_files

Domain
detected Domain: e.viewerupdates.next

XIOC detected Domain: e.viewerupdates.next

extracted_from_files

Domain
detected Domain: e.activelanguages.next

XIOC detected Domain: e.activelanguages.next

extracted_from_files

Domain
detected Domain: e.openedtextdocuments.next

XIOC detected Domain: e.openedtextdocuments.next

extracted_from_files

Domain
detected Domain: t.final

XIOC detected Domain: t.final

extracted_from_files

Domain
detected Domain: qr.author

XIOC detected Domain: qr.author

extracted_from_files

Domain
detected Domain: qr.case

XIOC detected Domain: qr.case

extracted_from_files

Domain
detected Domain: qr.select

XIOC detected Domain: qr.select

extracted_from_files

Domain
detected Domain: this.selectionschanges.next

XIOC detected Domain: this.selectionschanges.next

extracted_from_files

Domain
detected Domain: this.directory

XIOC detected Domain: this.directory

extracted_from_files

Domain
detected Domain: is.call

XIOC detected Domain: is.call

extracted_from_files

Domain
detected Domain: r.total

XIOC detected Domain: r.total

extracted_from_files

Domain
detected Domain: e.haveinitialextensionsloaded.next

XIOC detected Domain: e.haveinitialextensionsloaded.next

extracted_from_files

Domain
detected Domain: e.final

XIOC detected Domain: e.final

extracted_from_files

Domain
detected Domain: e.settings.value.final

XIOC detected Domain: e.settings.value.final

extracted_from_files

Domain
detected Domain: t.ping

XIOC detected Domain: t.ping

extracted_from_files

Domain
detected Domain: e.prototype.recycleasyncid.call

XIOC detected Domain: e.prototype.recycleasyncid.call

extracted_from_files

Domain
detected Domain: cmake.in

XIOC detected Domain: cmake.in

extracted_from_files

Domain
detected Domain: jr.map

XIOC detected Domain: jr.map

extracted_from_files

Domain
detected Domain: pe.now

XIOC detected Domain: pe.now

extracted_from_files

Domain
detected Domain: super.next

XIOC detected Domain: super.next

extracted_from_files

Domain
detected Domain: this.lexer.next

XIOC detected Domain: this.lexer.next

extracted_from_files

Domain
detected Domain: s.off

XIOC detected Domain: s.off

extracted_from_files

Domain
detected Domain: e.save

XIOC detected Domain: e.save

extracted_from_files

Domain
detected Domain: e.guide

XIOC detected Domain: e.guide

extracted_from_files

Domain
detected Domain: t.top

XIOC detected Domain: t.top

extracted_from_files

Domain
detected Domain: r.top

XIOC detected Domain: r.top

extracted_from_files

Domain
detected Domain: i.top-s.top

XIOC detected Domain: i.top-s.top

extracted_from_files

Domain
detected Domain: i.bottom-s.top

XIOC detected Domain: i.bottom-s.top

extracted_from_files

Domain
detected Domain: s.top

XIOC detected Domain: s.top

extracted_from_files

Domain
detected Domain: r-i.top

XIOC detected Domain: r-i.top

extracted_from_files

Domain
detected Domain: this.updates.next

XIOC detected Domain: this.updates.next

extracted_from_files

Domain
detected Domain: yi.select

XIOC detected Domain: yi.select

extracted_from_files

Domain
detected Domain: yi.case

XIOC detected Domain: yi.case

extracted_from_files

Domain
detected Domain: yi.author

XIOC detected Domain: yi.author

extracted_from_files

Domain
detected Domain: gi.map

XIOC detected Domain: gi.map

extracted_from_files

Domain
detected Domain: n.data.id

XIOC detected Domain: n.data.id

extracted_from_files

Domain
detected Domain: r.bottom-e.top

XIOC detected Domain: r.bottom-e.top

extracted_from_files

Domain
detected Domain: n.top

XIOC detected Domain: n.top

extracted_from_files

Domain
detected Domain: e.pin

XIOC detected Domain: e.pin

extracted_from_files

Domain
detected Domain: ou.top

XIOC detected Domain: ou.top

extracted_from_files

Domain
detected Domain: y.map

XIOC detected Domain: y.map

extracted_from_files

Domain
detected Domain: p.map

XIOC detected Domain: p.map

extracted_from_files

Domain
detected Domain: e.parentnode.host

XIOC detected Domain: e.parentnode.host

extracted_from_files

Domain
detected Domain: e.as

XIOC detected Domain: e.as

extracted_from_files

Domain
detected Domain: e.group

XIOC detected Domain: e.group

extracted_from_files

Domain
detected Domain: vu.md

XIOC detected Domain: vu.md

extracted_from_files

Domain
detected Domain: vu.sm

XIOC detected Domain: vu.sm

extracted_from_files

Domain
detected Domain: e.md

XIOC detected Domain: e.md

extracted_from_files

Domain
detected Domain: e.sm

XIOC detected Domain: e.sm

extracted_from_files

Domain
detected Domain: n.target

XIOC detected Domain: n.target

extracted_from_files

Domain
detected Domain: y.top

XIOC detected Domain: y.top

extracted_from_files

Domain
detected Domain: t.scrolltop-e.top

XIOC detected Domain: t.scrolltop-e.top

extracted_from_files

Domain
detected Domain: l.search

XIOC detected Domain: l.search

extracted_from_files

Domain
detected Domain: t.id

XIOC detected Domain: t.id

extracted_from_files

Domain
detected Domain: r.watches

XIOC detected Domain: r.watches

extracted_from_files

Domain
detected Domain: e.contributions.next

XIOC detected Domain: e.contributions.next

extracted_from_files

Domain
detected Domain: x.now

XIOC detected Domain: x.now

extracted_from_files

Domain
detected Domain: d.call

XIOC detected Domain: d.call

extracted_from_files

Domain
detected Domain: r.dot

XIOC detected Domain: r.dot

extracted_from_files

Domain
detected Domain: t.dot

XIOC detected Domain: t.dot

extracted_from_files

Domain
detected Domain: n.dot

XIOC detected Domain: n.dot

extracted_from_files

Domain
detected Domain: x.call

XIOC detected Domain: x.call

extracted_from_files

Domain
detected Domain: r.data.id

XIOC detected Domain: r.data.id

extracted_from_files

Domain
detected Domain: i.open

XIOC detected Domain: i.open

extracted_from_files

Domain
detected Domain: release.id

XIOC detected Domain: release.id

extracted_from_files

Domain
detected Domain: browser.runtime.id

XIOC detected Domain: browser.runtime.id

extracted_from_files

Domain
detected Domain: r.tab

XIOC detected Domain: r.tab

extracted_from_files

Domain
detected Domain: o.sender.tab

XIOC detected Domain: o.sender.tab

extracted_from_files

Domain
detected Domain: r.post

XIOC detected Domain: r.post

extracted_from_files

Domain
detected Domain: o.post

XIOC detected Domain: o.post

extracted_from_files

Domain
detected Domain: i.host

XIOC detected Domain: i.host

extracted_from_files

Domain
detected Domain: o.host

XIOC detected Domain: o.host

extracted_from_files

Domain
detected Domain: rd.id

XIOC detected Domain: rd.id

extracted_from_files

Domain
detected Domain: dd.id

XIOC detected Domain: dd.id

extracted_from_files

Domain
detected Domain: fd.id

XIOC detected Domain: fd.id

extracted_from_files

Domain
detected Domain: bd.id

XIOC detected Domain: bd.id

extracted_from_files

Domain
detected Domain: yd.id

XIOC detected Domain: yd.id

extracted_from_files

Domain
detected Domain: e.spans.map

XIOC detected Domain: e.spans.map

extracted_from_files

Domain
detected Domain: s.name

XIOC detected Domain: s.name

extracted_from_files

Domain
detected Domain: t.constructor.name

XIOC detected Domain: t.constructor.name

extracted_from_files

Domain
detected Domain: td.id

XIOC detected Domain: td.id

extracted_from_files

Domain
detected Domain: t.event.target

XIOC detected Domain: t.event.target

extracted_from_files

Domain
detected Domain: t.global

XIOC detected Domain: t.global

extracted_from_files

Domain
detected Domain: e.to

XIOC detected Domain: e.to

extracted_from_files

Domain
detected Domain: t.app

XIOC detected Domain: t.app

extracted_from_files

Domain
detected Domain: new.target.prototype.constructor.name

XIOC detected Domain: new.target.prototype.constructor.name

extracted_from_files

Domain
detected Domain: constructor.name

XIOC detected Domain: constructor.name

extracted_from_files

Domain
detected Domain: e.sdk.name

XIOC detected Domain: e.sdk.name

extracted_from_files

Domain
detected Domain: e.breadcrumbs.map

XIOC detected Domain: e.breadcrumbs.map

extracted_from_files

Domain
detected Domain: e.contexts.trace.data

XIOC detected Domain: e.contexts.trace.data

extracted_from_files

Domain
detected Domain: n.contexts.trace.data

XIOC detected Domain: n.contexts.trace.data

extracted_from_files

Domain
detected Domain: init6.call

XIOC detected Domain: init6.call

extracted_from_files

Domain
detected Domain: lp.ph

XIOC detected Domain: lp.ph

extracted_from_files

Domain
detected Domain: t.user.id

XIOC detected Domain: t.user.id

extracted_from_files

Domain
detected Domain: t.user.email

XIOC detected Domain: t.user.email

extracted_from_files

Domain
detected Domain: span.transaction.name

XIOC detected Domain: span.transaction.name

extracted_from_files

Domain
detected Domain: s.id

XIOC detected Domain: s.id

extracted_from_files

Domain
detected Domain: e.chrome

XIOC detected Domain: e.chrome

extracted_from_files

Domain
detected Domain: cp.id

XIOC detected Domain: cp.id

extracted_from_files

Domain
detected Domain: init.call

XIOC detected Domain: init.call

extracted_from_files

Domain
detected Domain: dp.id

XIOC detected Domain: dp.id

extracted_from_files

Domain
detected Domain: init2.call

XIOC detected Domain: init2.call

extracted_from_files

Domain
detected Domain: init3.call

XIOC detected Domain: init3.call

extracted_from_files

Domain
detected Domain: init4.call

XIOC detected Domain: init4.call

extracted_from_files

Domain
detected Domain: init5.call

XIOC detected Domain: init5.call

extracted_from_files

Domain
detected Domain: cf.page

XIOC detected Domain: cf.page

extracted_from_files

Domain
detected Domain: i.id

XIOC detected Domain: i.id

extracted_from_files

Domain
detected Domain: i.latestsettings.id

XIOC detected Domain: i.latestsettings.id

extracted_from_files

Domain
detected Domain: r.final

XIOC detected Domain: r.final

extracted_from_files

Domain
detected Domain: n.final

XIOC detected Domain: n.final

extracted_from_files

Domain
detected Domain: kf.call

XIOC detected Domain: kf.call

extracted_from_files

Domain
detected Domain: r.mechanism.data

XIOC detected Domain: r.mechanism.data

extracted_from_files

Domain
detected Domain: this.data.group

XIOC detected Domain: this.data.group

extracted_from_files

Domain
detected Domain: this.optimisticdata.group

XIOC detected Domain: this.optimisticdata.group

extracted_from_files

Domain
detected Domain: t.prototype.read

XIOC detected Domain: t.prototype.read

extracted_from_files

Domain
detected Domain: t.prototype.watch

XIOC detected Domain: t.prototype.watch

extracted_from_files

Domain
detected Domain: i.data

XIOC detected Domain: i.data

extracted_from_files

Domain
detected Domain: t.onwatchupdated.call

XIOC detected Domain: t.onwatchupdated.call

extracted_from_files

Domain
detected Domain: e.page

XIOC detected Domain: e.page

extracted_from_files

Domain
detected Domain: a.read

XIOC detected Domain: a.read

extracted_from_files

Domain
detected Domain: r.read

XIOC detected Domain: r.read

extracted_from_files

Domain
detected Domain: t.info

XIOC detected Domain: t.info

extracted_from_files

Domain
detected Domain: f.store

XIOC detected Domain: f.store

extracted_from_files

Domain
detected Domain: d.info

XIOC detected Domain: d.info

extracted_from_files

Domain
detected Domain: advanced.md

XIOC detected Domain: advanced.md

extracted_from_files

Domain
detected Domain: r.canon

XIOC detected Domain: r.canon

extracted_from_files

Domain
detected Domain: r.store

XIOC detected Domain: r.store

extracted_from_files

Domain
detected Domain: n.store

XIOC detected Domain: n.store

extracted_from_files

Domain
detected Domain: e.store

XIOC detected Domain: e.store

extracted_from_files

Domain
detected Domain: s.store

XIOC detected Domain: s.store

extracted_from_files

Domain
detected Domain: n.cache.data

XIOC detected Domain: n.cache.data

extracted_from_files

Domain
detected Domain: n.read

XIOC detected Domain: n.read

extracted_from_files

Domain
detected Domain: i.read

XIOC detected Domain: i.read

extracted_from_files

Domain
detected Domain: o.id

XIOC detected Domain: o.id

extracted_from_files

Domain
detected Domain: o.group

XIOC detected Domain: o.group

extracted_from_files

Domain
detected Domain: e.prototype.findchildrefids.call

XIOC detected Domain: e.prototype.findchildrefids.call

extracted_from_files

Domain
detected Domain: t.group

XIOC detected Domain: t.group

extracted_from_files

Domain
detected Domain: this.canon

XIOC detected Domain: this.canon

extracted_from_files

Domain
detected Domain: e.canon

XIOC detected Domain: e.canon

extracted_from_files

Domain
detected Domain: e.context.store

XIOC detected Domain: e.context.store

extracted_from_files

Domain
detected Domain: window.top

XIOC detected Domain: window.top

extracted_from_files

Domain
detected Domain: e.resetstorecallbacks.map

XIOC detected Domain: e.resetstorecallbacks.map

extracted_from_files

Domain
detected Domain: e.clearstorecallbacks.map

XIOC detected Domain: e.clearstorecallbacks.map

extracted_from_files

Domain
detected Domain: this.querymanager.link

XIOC detected Domain: this.querymanager.link

extracted_from_files

Domain
detected Domain: this.read

XIOC detected Domain: this.read

extracted_from_files

Domain
detected Domain: this.group

XIOC detected Domain: this.group

extracted_from_files

Domain
detected Domain: this.data

XIOC detected Domain: this.data

extracted_from_files

Domain
detected Domain: e.selections.map

XIOC detected Domain: e.selections.map

extracted_from_files

Domain
detected Domain: this.cache.watch

XIOC detected Domain: this.cache.watch

extracted_from_files

Domain
detected Domain: r.result.data

XIOC detected Domain: r.result.data

extracted_from_files

Domain
detected Domain: e.link

XIOC detected Domain: e.link

extracted_from_files

Domain
detected Domain: this.link

XIOC detected Domain: this.link

extracted_from_files

Domain
detected Domain: sl.call

XIOC detected Domain: sl.call

extracted_from_files

Domain
detected Domain: i.definitions.map

XIOC detected Domain: i.definitions.map

extracted_from_files

Domain
detected Domain: lc.call

XIOC detected Domain: lc.call

extracted_from_files

Domain
detected Domain: bc.call

XIOC detected Domain: bc.call

extracted_from_files

Domain
detected Domain: wc.call

XIOC detected Domain: wc.call

extracted_from_files

Domain
detected Domain: jc.call

XIOC detected Domain: jc.call

extracted_from_files

Domain
detected Domain: tu.call

XIOC detected Domain: tu.call

extracted_from_files

Domain
detected Domain: this.observer

XIOC detected Domain: this.observer

extracted_from_files

Domain
detected Domain: mu.call

XIOC detected Domain: mu.call

extracted_from_files

Domain
detected Domain: this.commandexecutions.next

XIOC detected Domain: this.commandexecutions.next

extracted_from_files

URL
detected URL: http://a

XIOC detected URL: http://a

extracted_from_files

Domain
detected Domain: this.props.action.id

XIOC detected Domain: this.props.action.id

extracted_from_files

Domain
detected Domain: window.open

XIOC detected Domain: window.open

extracted_from_files

Domain
detected Domain: i.subject.id

XIOC detected Domain: i.subject.id

extracted_from_files

Domain
detected Domain: a.children.map

XIOC detected Domain: a.children.map

extracted_from_files

Domain
detected Domain: this.state.top

XIOC detected Domain: this.state.top

extracted_from_files

Domain
detected Domain: this.tokenizer.hr

XIOC detected Domain: this.tokenizer.hr

extracted_from_files

Domain
detected Domain: this.tokenizer.space

XIOC detected Domain: this.tokenizer.space

extracted_from_files

Domain
detected Domain: d.br

XIOC detected Domain: d.br

extracted_from_files

Domain
detected Domain: d.link

XIOC detected Domain: d.link

extracted_from_files

Domain
detected Domain: ed.hr

XIOC detected Domain: ed.hr

extracted_from_files

Domain
detected Domain: this.lexer.state.top

XIOC detected Domain: this.lexer.state.top

extracted_from_files

Domain
detected Domain: fd.sm

XIOC detected Domain: fd.sm

extracted_from_files

Domain
detected Domain: e.walktokens.call

XIOC detected Domain: e.walktokens.call

extracted_from_files

Domain
detected Domain: t.br

XIOC detected Domain: t.br

extracted_from_files

Domain
detected Domain: t.link

XIOC detected Domain: t.link

extracted_from_files

Domain
detected Domain: this.renderer.hr

XIOC detected Domain: this.renderer.hr

extracted_from_files

Domain
detected Domain: this.tokenizer.br

XIOC detected Domain: this.tokenizer.br

extracted_from_files

Domain
detected Domain: this.tokenizer.link

XIOC detected Domain: this.tokenizer.link

extracted_from_files

Domain
detected Domain: fg.map

XIOC detected Domain: fg.map

extracted_from_files

Domain
detected Domain: bitbucket.org

XIOC detected Domain: bitbucket.org

extracted_from_files

Domain
detected Domain: this.componentupdates.next

XIOC detected Domain: this.componentupdates.next

extracted_from_files

Domain
detected Domain: t.action.id

XIOC detected Domain: t.action.id

extracted_from_files

Domain
detected Domain: fp.call

XIOC detected Domain: fp.call

extracted_from_files

Domain
detected Domain: bp.page

XIOC detected Domain: bp.page

extracted_from_files

Domain
detected Domain: t.contents.map

XIOC detected Domain: t.contents.map

extracted_from_files

Domain
detected Domain: file-title.name

XIOC detected Domain: file-title.name

extracted_from_files

Domain
detected Domain: a.id

XIOC detected Domain: a.id

extracted_from_files

Domain
detected Domain: sb.ph

XIOC detected Domain: sb.ph

extracted_from_files

Domain
detected Domain: n.mechanism.data

XIOC detected Domain: n.mechanism.data

extracted_from_files

Domain
detected Domain: ov.call

XIOC detected Domain: ov.call

extracted_from_files

Domain
detected Domain: window.location.search

XIOC detected Domain: window.location.search

extracted_from_files

Domain
detected Domain: n.open

XIOC detected Domain: n.open

extracted_from_files

Domain
detected Domain: n.values.map

XIOC detected Domain: n.values.map

extracted_from_files

Domain
detected Domain: n.fields.map

XIOC detected Domain: n.fields.map

extracted_from_files

Domain
detected Domain: n.run

XIOC detected Domain: n.run

extracted_from_files

Domain
detected Domain: e.diffdetails.properties

XIOC detected Domain: e.diffdetails.properties

extracted_from_files

Domain
detected Domain: window.location.host

XIOC detected Domain: window.location.host

extracted_from_files

Domain
detected Domain: diffusion.repository.search

XIOC detected Domain: diffusion.repository.search

extracted_from_files

Domain
detected Domain: ty.next

XIOC detected Domain: ty.next

extracted_from_files

Domain
detected Domain: o.definitions.map

XIOC detected Domain: o.definitions.map

extracted_from_files

Domain
detected Domain: px.call

XIOC detected Domain: px.call

extracted_from_files

Domain
detected Domain: n.result.data

XIOC detected Domain: n.result.data

extracted_from_files

Domain
detected Domain: qs.call

XIOC detected Domain: qs.call

extracted_from_files

Domain
detected Domain: ks.call

XIOC detected Domain: ks.call

extracted_from_files

Domain
detected Domain: o.stream

XIOC detected Domain: o.stream

extracted_from_files

Domain
detected Domain: r.link

XIOC detected Domain: r.link

extracted_from_files

Domain
detected Domain: n.watches

XIOC detected Domain: n.watches

extracted_from_files

Domain
detected Domain: h.info

XIOC detected Domain: h.info

extracted_from_files

Domain
detected Domain: u.store

XIOC detected Domain: u.store

extracted_from_files

Domain
detected Domain: s.read

XIOC detected Domain: s.read

extracted_from_files

Domain
detected Domain: o.read

XIOC detected Domain: o.read

extracted_from_files

Domain
detected Domain: r.cache.data

XIOC detected Domain: r.cache.data

extracted_from_files

Domain
detected Domain: a.store

XIOC detected Domain: a.store

extracted_from_files

Domain
detected Domain: yc.id

XIOC detected Domain: yc.id

extracted_from_files

Domain
detected Domain: r.contexts.trace.data

XIOC detected Domain: r.contexts.trace.data

extracted_from_files

Domain
detected Domain: gk.id

XIOC detected Domain: gk.id

extracted_from_files

Domain
detected Domain: pk.id

XIOC detected Domain: pk.id

extracted_from_files

Domain
detected Domain: sc.map

XIOC detected Domain: sc.map

extracted_from_files

Domain
detected Domain: o.latestsettings.id

XIOC detected Domain: o.latestsettings.id

extracted_from_files

Domain
detected Domain: n.canon

XIOC detected Domain: n.canon

extracted_from_files

Domain
detected Domain: o.open

XIOC detected Domain: o.open

extracted_from_files

Domain
detected Domain: co.id

XIOC detected Domain: co.id

extracted_from_files

Domain
detected Domain: no.id

XIOC detected Domain: no.id

extracted_from_files

Domain
detected Domain: eo.id

XIOC detected Domain: eo.id

extracted_from_files

Domain
detected Domain: wc.id

XIOC detected Domain: wc.id

extracted_from_files

Domain
detected Domain: zc.id

XIOC detected Domain: zc.id

extracted_from_files

Domain
detected Domain: a.host

XIOC detected Domain: a.host

extracted_from_files

Domain
detected Domain: ei.case

XIOC detected Domain: ei.case

extracted_from_files

Domain
detected Domain: ei.author

XIOC detected Domain: ei.author

extracted_from_files

Domain
detected Domain: vi.map

XIOC detected Domain: vi.map

extracted_from_files

Domain
detected Domain: de.now

XIOC detected Domain: de.now

extracted_from_files

Domain
detected Domain: c.name

XIOC detected Domain: c.name

extracted_from_files

Domain
detected Domain: c.host

XIOC detected Domain: c.host

extracted_from_files

Domain
detected Domain: k.next

XIOC detected Domain: k.next

extracted_from_files

Domain
detected Domain: xd.link

XIOC detected Domain: xd.link

extracted_from_files

Domain
detected Domain: sd.hr

XIOC detected Domain: sd.hr

extracted_from_files

Domain
detected Domain: c.search

XIOC detected Domain: c.search

extracted_from_files

Domain
detected Domain: qu.md

XIOC detected Domain: qu.md

extracted_from_files

Domain
detected Domain: qu.sm

XIOC detected Domain: qu.sm

extracted_from_files

Domain
detected Domain: au.top

XIOC detected Domain: au.top

extracted_from_files

Domain
detected Domain: ei.select

XIOC detected Domain: ei.select

extracted_from_files

Domain
detected Domain: lb.call

XIOC detected Domain: lb.call

extracted_from_files

Domain
detected Domain: sg.map

XIOC detected Domain: sg.map

extracted_from_files

Domain
detected Domain: n.action.id

XIOC detected Domain: n.action.id

extracted_from_files

Domain
detected Domain: up.call

XIOC detected Domain: up.call

extracted_from_files

Domain
detected Domain: wp.page

XIOC detected Domain: wp.page

extracted_from_files

Domain
detected Domain: bd.sm

XIOC detected Domain: bd.sm

extracted_from_files

Domain
detected Domain: xd.br

XIOC detected Domain: xd.br

extracted_from_files

Domain
detected Domain: fs.call

XIOC detected Domain: fs.call

extracted_from_files

Domain
detected Domain: we.call

XIOC detected Domain: we.call

extracted_from_files

Domain
detected Domain: qe.call

XIOC detected Domain: qe.call

extracted_from_files

Domain
detected Domain: ge.call

XIOC detected Domain: ge.call

extracted_from_files

Domain
detected Domain: ee.call

XIOC detected Domain: ee.call

extracted_from_files

Domain
detected Domain: yv.next

XIOC detected Domain: yv.next

extracted_from_files

Domain
detected Domain: nb.ph

XIOC detected Domain: nb.ph

extracted_from_files

Domain
detected Domain: bt.ph

XIOC detected Domain: bt.ph

extracted_from_files

Domain
detected Domain: vt.id

XIOC detected Domain: vt.id

extracted_from_files

Domain
detected Domain: ue.call

XIOC detected Domain: ue.call

extracted_from_files

Domain
detected Domain: qo.next

XIOC detected Domain: qo.next

extracted_from_files

Domain
detected Domain: g.call

XIOC detected Domain: g.call

extracted_from_files

Domain
detected Domain: cl.map

XIOC detected Domain: cl.map

extracted_from_files

Domain
detected Domain: xs.call

XIOC detected Domain: xs.call

extracted_from_files

Domain
detected Domain: gr.page

XIOC detected Domain: gr.page

extracted_from_files

Domain
detected Domain: pr.id

XIOC detected Domain: pr.id

extracted_from_files

Domain
detected Domain: nr.id

XIOC detected Domain: nr.id

extracted_from_files

Domain
detected Domain: tr.id

XIOC detected Domain: tr.id

extracted_from_files

Domain
detected Domain: er.id

XIOC detected Domain: er.id

extracted_from_files

Domain
detected Domain: gr.id

XIOC detected Domain: gr.id

extracted_from_files

Domain
detected Domain: hn.id

XIOC detected Domain: hn.id

extracted_from_files

Domain
detected Domain: e.currenttarget.id

XIOC detected Domain: e.currenttarget.id

extracted_from_files

Domain
detected Domain: mu.now

XIOC detected Domain: mu.now

extracted_from_files

Domain
detected Domain: d.id

XIOC detected Domain: d.id

extracted_from_files

Domain
detected Domain: o.top

XIOC detected Domain: o.top

extracted_from_files

Domain
detected Domain: c.style

XIOC detected Domain: c.style

extracted_from_files

Security Analysis Summary

Security Analysis Overview

Sourcegraph for Firefox is a Firefox Add-ons extension published by Sourcegraph. Version 23.4.14.1343 has been analyzed by the Risky Plugins security platform, receiving a risk score of 54.22/100 (MEDIUM risk) based on 1495 security findings.

Risk Assessment

This extension presents moderate security risk. Several findings were detected that may warrant attention. Users should carefully review the permissions and findings before installation.

Findings Breakdown

  • High: 672 finding(s)
  • Medium: 823 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

Sourcegraph for Firefox is published by Sourcegraph on the Firefox Add-ons marketplace. The extension has approximately 459 users.

Recommendation

Exercise caution with this extension. Review the detailed findings and ensure the requested permissions align with the extension's stated functionality before installation.

Frequently Asked Questions