Firefox Add-ons

DM Developer

by Jimmy Pautz · 6 users · 5.0 rating
02525ed1-0366-5423-a2e6-a45287c57195 | v26.9.10
39/ 100
LOW risk
No change since v26.9.9
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
2 weeks ago
Version
v26.9.10
Artifact
SHA256 FCD…CA9
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

2 detail rows

Publisher Evidence

Limited evidence

Jimmy Pautz

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

24
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Limited signal
Limited
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

1
Network

Requested Permissions

2 permissions
storage
Low
*://*.digitalmeasures.com/login/*
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

This extension presents a classic false positive scenario driven by test file noise. The extension "DM Developer" is described as an internal tool for Digital Measures developers to enhance their AI administrative backend, requiring backend access.

Obfuscation Findings Are Test File Noise: All 5 obfuscation findings (OBFUSCATION-FUNCTION_INDIRECT) appear exclusively in test files: tests/content-scripts.test.js:19, tests/admin-tools.test.js:11, tests/reports.test.js:13, tests/task-manager.test.js:11, and tests/ui-scripts.test.js:12. The function_indirect pattern in test files is a known false positive—testing frameworks commonly use indirect function calls for mocking, stubbing, and test isolation. These are not obfuscation techniques in production code.

Network Activity Is Benign: The single network finding (NET-FETCH-scripts/Common.js-85) shows a standard fetch call in production code. This is normal behavior for any extension communicating with a backend service. No suspicious domains are present in the evidence—zero IoC findings means no external domain extraction occurred.

No Malware Indicators: The findings summary shows 0 malware signatures, 0 malware findings, and 0 code-smell findings. The extension lacks any high-confidence threat indicators: no credential theft patterns, no browser hijacking domains, no typosquatting, and no suspicious network destinations.

Counterargument and Rebuttal: A skeptic might argue that the anonymous developer (empty developer_name) combined with obfuscation patterns warrants concern. However, the obfuscation is demonstrably in test files, not production code. Internal developer tools often lack formal publisher attribution because they are not intended for public distribution. The 6-user count confirms this is a niche internal tool, not a public-facing extension. The absence of malware signatures, suspicious domains, or credential access patterns outweighs the anonymous publisher signal. If this were truly malicious, we would expect at least one of: malware signatures, suspicious network domains, or obfuscation in production scripts—not test files.

Conclusion: The findings are consistent with a legitimate internal developer tool where automated analysis flagged test file patterns as obfuscation. No evidence of malicious behavior exists.

Key Reasons

  • All obfuscation findings are in test files (.test.js), not production code
  • Zero malware signatures and zero suspicious network domains
  • Single fetch call is normal backend communication behavior
  • Extension appears to be internal developer tool with 6 users
  • No credential theft, hijacking, or data exfiltration patterns detected

False Positive Considerations

  • Obfuscation patterns in test files
  • Test framework indirect function calls misclassified as obfuscation
  • No production code obfuscation detected

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.

Firefox version history

Risk trend by version

9 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
39
Change since first
-15
Change from previous
No change
Versions:
First analyzed version
26.3.13.1
Mar 14, 2026
Risk range
39 to 54
Across analyzed versions
Latest analyzed version
26.9.10
Sep 11, 2026
Selected version
low
Version
v26.9.10
2 weeks ago
Risk score
39
Findings
2
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

If you have access to Activity Insight, some of the UI wasn't well optimized for Developers or Consultants. This addon gives users the ability to toggle on fixes to many common UI/UX issues. This addon gives the ability to <ul><li>Expand the DM utilities out of the navigation</li><li>Add work request specific links</li><li>Add work request specific FOCUS tools</li><li>Rename browser tab titles</li><li>More!</li> For access to AI, you need to purchase it: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/d3113ba7b71b7243bb561c4ba383ef161c96351e1b7e622bab8fc2fb733e8048/https%3A//digitalmeasures.com" rel="nofollow">https://digitalmeasures.com</a> or be an employee at DM.</ul>

Frequently Asked Questions