Chrome Web Store Verified

Adobe Experience Cloud Visual Editing Helper

by [email protected] · 20.0K users · 2.9 rating
022e676d-3abe-5266-be9b-cce62a4a7fa7 | v1.5.10
55/ 100
MEDIUM risk
+14 since v1.5.9
Risk verdict
Review before use

Score-based assessment (medium risk, 55/100). No analyst review available.

Analysis record

Analysed
1 weeks ago
Version
v1.5.10
Artifact
SHA256 BF7…D8A
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

34 detail rows

YARA Rule Matches

12 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall persistence mechanism 2
popup.htmlbackground.js
-
LOWpostinstall crypto operations 5
_metadata/verified_contents.jsonauthoring.jsassets/deviceEmulation.js +2 more
-
LOWpostinstall system command 4
authoring.jsassets/setupViewsTrigger.jspopup.html +1 more
-
LOWpostinstall file manipulation 7
rules.jsonpopup.jsbackground.js +4 more
-
LOWpostinstall network communication 5
authoring.jspopup.jsassets/setupViewsTrigger.js +2 more
-
LOWpostinstall registry modification 1
background.js
-
LOWpostinstall obfuscation 4
authoring.cssbackground.jsauthoring.js +1 more
-
LOWNoUseEval 1
authoring.js
-
LOWpostinstall file download 1
authoring.js
-
LOWUntrustedContentShouldNotBeIncluded 1
authoring.js
-
LOWSQLInjection 1
authoring.js
-
LOWNoUseWeakRandom 1
authoring.js
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

87 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Low

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

79
Noisy-finding weight
x1.00
Publisher domain
adobe.com
Trusted match
Store verification signal
Limited signal
Limited
Extension portfolio
25
Portfolio

12 evidence rows available.

Finding Categories

1
Obfuscation
87
IoC Indicators

YARA Rules Matched

12 rules(33 hits)
postinstall persistence mechanism postinstall crypto operations postinstall system command postinstall file manipulation postinstall network communication postinstall registry modification postinstall obfuscation NoUseEval postinstall file download UntrustedContentShouldNotBeIncluded SQLInjection NoUseWeakRandom

Requested Permissions

8 permissions
<all_urls>

Access and modify data on every website you visit

Dangerous
cookies

Read and modify cookies on all sites

High
webRequest

Intercept, modify, and block all network requests

High
browsingData
Medium
declarativeNetRequest
Low
scripting
Low
storage
Low
webNavigation
Low

Security Analysis Summary

Security Analysis Overview

Adobe Experience Cloud Visual Editing Helper is a Chrome Web Store extension published by [email protected]. Version 1.5.10 has been analyzed by the Risky Plugins security platform, receiving a risk score of 54.53/100 (MEDIUM risk) based on 121 security findings.

Risk Assessment

This extension presents moderate security risk. Several findings were detected that may warrant attention. Users should carefully review the permissions and findings before installation.

Findings Breakdown

  • Medium: 88 finding(s)
  • Low: 33 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

Adobe Experience Cloud Visual Editing Helper is published by [email protected] on the Chrome Web Store marketplace. The extension has approximately 20K users.

Recommendation

Exercise caution with this extension. Review the detailed findings and ensure the requested permissions align with the extension's stated functionality before installation.

Chrome version history

Risk trend by version

4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
55
Change since first
+11
Change from previous
+14
Versions:
First analyzed version
1.5.3
Mar 12, 2026
Risk range
29 to 55
Across analyzed versions
Latest analyzed version
1.5.10
Sep 20, 2026
Selected version
medium
Version
v1.5.10
1 weeks ago
Risk score
55
Findings
121
Change vs previous
+14

Pick any point on the chart to explore that version's code below.

About This Extension

The Visual Editing Helper Chrome extension allows Adobe Experience Cloud users to load their website into Adobe Target or Adobe Journey Optimizer and to use a visual WYSIWYG editor to personalize it. The extension solves site-loading issues for which customers now rely on the Target Enhanced Experience Composer or third-party extensions to be able to author their websites. Benefits of using the Visual Editing Helper extension: - All iframe busting headers, such as X-Frame-Options and Content-Security-Policy, are implicitly removed from the website to enable authoring. - Extension sets SameSite attribute to the value "None" for the website's session cookies in order to be able to login using the visual editor. - Customers new to Target or to Journey Optimizer can use the extension to experiment even if their IT developers have not yet implemented Target or Journey Optimizer on their websites.

Frequently Asked Questions