Canned replies, canned responses, canned messages for any website
Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 10 months ago
- Version
- v1.0.1
- Artifact
- SHA256 F17…149
- Source
- Findings (non-IoC)
No Findings
All security checks passed
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
No Threats Detected
This extension passed all security checks
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
Security Analysis: Canned Replies Extension
Extension Overview
This Chrome extension (version 1.0.1) provides canned reply functionality for websites and social networks. The developer is listed as [email protected] with 21 users.
Finding Analysis
IoC Findings (145 total)
The IoC findings are entirely false positives from the XIOC extractor. The evidence shows:
XIOC-DOMAIN-securetoken.googleapis.com- Legitimate Google authentication service, not suspiciousXIOC-DOMAIN-n.target- Property access chain misread as domain (not a valid TLD)XIOC-DOMAIN-window.open- JavaScript API method, not a domainXIOC-DOMAIN-t.ping,XIOC-DOMAIN-l.id,XIOC-DOMAIN-i.id,XIOC-DOMAIN-t.tips- All property access patterns incorrectly flagged as domains
These match the documented XIOC extractor garbage patterns: property access chains like b.call, h.next, g.id being misinterpreted as domains. None of these represent actual network destinations.
Network Findings (10 total)
Generic fetch detections in:
src/pages/background/index.js:466and:610- Background script network callsviews/pages/home.js:1andviews/pages/search.js:1- UI page fetch callsscripts/suggest/sites/facebook.js:1- Facebook site integration
These are standard fetch API calls without any specific suspicious domains attached. The Facebook integration aligns with the extension's stated purpose of working with social networks.
Code-Smell Findings (65 total)
All code-smell findings are classified as low severity and represent benign patterns like basic JavaScript constructs (fetch, API calls, crypto). No malware signatures are present.
Malware & Obfuscation
Zero malware signatures and zero obfuscation findings. This is significant—actual malicious extensions typically show at least one malware signature or obfuscation technique.
Counterargument Consideration
A skeptic might argue that 220 total findings with 145 IoCs indicates suspicious activity. However, this reasoning ignores the documented false-positive patterns. The XIOC extractor is known to produce massive false-positive volumes from property access chains. The finding count is meaningless without examining the nature of findings. The only actual IoC (securetoken.googleapis.com) is a legitimate Google service. No custom search engines, credential theft patterns, or suspicious domains exist in the evidence. The extension's behavior (fetch calls to Facebook and background scripts) matches its declared purpose of managing canned replies across websites.
Conclusion
This is a utility extension with findings driven entirely by known CVEQ false-positive patterns. No evidence of malicious intent or behavior.
Key Reasons
- Zero malware signatures detected
- All IoC findings are documented XIOC extractor false positives
- Network findings show only generic fetch calls without suspicious domains
- Extension purpose matches observed behavior (Facebook integration for social network replies)
False Positive Considerations
- XIOC property access chain misinterpretation (n.target, t.ping, l.id, i.id, t.tips)
- JavaScript API misread as domain (window.open)
- Legitimate Google domain (securetoken.googleapis.com)
- Generic code-smell rules on JavaScript constructs
Reviewed 2026-05-09; recommended action: suppress false positive; model confidence 85%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Ship Xanh copy sản phẩm, nhân bản shop, hiển thị % phí sàn, lượt bán tháng
[email protected]
Edge Translate - Browser Translator | PDF Translation | MV3 | Open Source
[email protected]
Intelbras Cloud
[email protected]
SlingPlayer for DISH Anywhere
Unknown Developer
My Jobscore
[email protected]
种草星球-TikTok爆单神器,商品自动提报采集邀评【永久免费】
[email protected]