DM Developer
Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 2 weeks ago
- Version
- v26.9.10
- Artifact
- SHA256 FCD…CA9
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
Limited evidenceJimmy Pautz
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
Requested Permissions
2 permissionsAI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
This extension presents a classic false positive scenario driven by test file noise. The extension "DM Developer" is described as an internal tool for Digital Measures developers to enhance their AI administrative backend, requiring backend access.
Obfuscation Findings Are Test File Noise: All 5 obfuscation findings (OBFUSCATION-FUNCTION_INDIRECT) appear exclusively in test files: tests/content-scripts.test.js:19, tests/admin-tools.test.js:11, tests/reports.test.js:13, tests/task-manager.test.js:11, and tests/ui-scripts.test.js:12. The function_indirect pattern in test files is a known false positive—testing frameworks commonly use indirect function calls for mocking, stubbing, and test isolation. These are not obfuscation techniques in production code.
Network Activity Is Benign: The single network finding (NET-FETCH-scripts/Common.js-85) shows a standard fetch call in production code. This is normal behavior for any extension communicating with a backend service. No suspicious domains are present in the evidence—zero IoC findings means no external domain extraction occurred.
No Malware Indicators: The findings summary shows 0 malware signatures, 0 malware findings, and 0 code-smell findings. The extension lacks any high-confidence threat indicators: no credential theft patterns, no browser hijacking domains, no typosquatting, and no suspicious network destinations.
Counterargument and Rebuttal: A skeptic might argue that the anonymous developer (empty developer_name) combined with obfuscation patterns warrants concern. However, the obfuscation is demonstrably in test files, not production code. Internal developer tools often lack formal publisher attribution because they are not intended for public distribution. The 6-user count confirms this is a niche internal tool, not a public-facing extension. The absence of malware signatures, suspicious domains, or credential access patterns outweighs the anonymous publisher signal. If this were truly malicious, we would expect at least one of: malware signatures, suspicious network domains, or obfuscation in production scripts—not test files.
Conclusion: The findings are consistent with a legitimate internal developer tool where automated analysis flagged test file patterns as obfuscation. No evidence of malicious behavior exists.
Key Reasons
- All obfuscation findings are in test files (.test.js), not production code
- Zero malware signatures and zero suspicious network domains
- Single fetch call is normal backend communication behavior
- Extension appears to be internal developer tool with 6 users
- No credential theft, hijacking, or data exfiltration patterns detected
False Positive Considerations
- Obfuscation patterns in test files
- Test framework indirect function calls misclassified as obfuscation
- No production code obfuscation detected
Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.
Firefox version history
Risk trend by version
9 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace