Is "HubMerge" on Chrome Web Store Safe to Install?
Detect and merge duplicate HubSpot properties with ease. This Chrome extension automatically identifies similar or redundant properties in your HubSpot CRM, highlights potential duplicates, and helps you clean up your data for better organization and reporting. Improve data quality, reduce clutter, and streamline your HubSpot property management in just a few clicks. 🚀 Get Started Install HubMerge to quickly detect and merge duplicate properties in your HubSpot CRM—no manual cleanup required. ✔ Automatically identifies duplicate or similar properties ✔ Merge properties in just a few clicks ✔ Keep your HubSpot CRM clean, organized, and reliable ✔ Save time and reduce data clutter Support: [email protected]
Risk Assessment
Analyzed3 security findings detected across all analyzers
Chrome extension requesting 5 permissions
Severity Breakdown
Finding Categories
Requested Permissions
5 permissionsAbout This Extension
Detailed Findings
3 totalAI Security Report
AI Security Review
Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-04-27. The review verdict is likely false positive with 85% confidence.
Recommended action: suppress false positive.
Risk context: HIGH risk, score 68/100.
Evidence context: threat category none; evidence quality moderate.
The HubMerge extension exhibits a classic false-positive profile driven entirely by XIOC extractor garbage. All 133 IoC findings are property access chain misinterpretations, not real network domains. Specific examples include XIOC-DOMAIN-o.call (function property access), XIOC-DOMAIN-h.id (DOM element ID property), XIOC-DOMAIN-b.map (Array.map method), and XIOC-DOMAIN-j.now (Date.now property). These patterns match the documented XIOC false-positive behavior where JavaScript property chains like object.property are misread as domain names. The evidence explicitly states these were extracted_from_files with no actual network destinations.
Zero malware signatures were detected across all 154 total findings. The findings summary shows "malware-signature":"0" and "malware":"0", which is a critical distinction. Malware signatures represent confirmed malicious code patterns, while the 18 code-smell findings are classified as low-severity and trigger on basic JavaScript patterns per the CVEQ documentation. The 2 network findings lack specific domain details that would indicate actual data exfiltration or C2 communication.
The extension's metadata is consistent with legitimate behavior. The name "HubMerge" aligns with the description "Merge HubSpot properties easily" - a reasonable functionality for a HubSpot integration tool. The developer email [email protected] provides attribution rather than anonymity. While the user count of 1 indicates a very new or niche extension, this alone is not a threat indicator.
The strongest counterargument would be the high finding volume of 154 total detections. However, the guidelines explicitly state "IoC COUNT alone is meaningless. Only specific, non-generic suspicious domains matter." None of the 133 IoCs represent actual suspicious domains - they are all property access chains like r.style, z.style, and sl.now. The finding count is inflated by known XIOC noise patterns, not actual malicious infrastructure. Without malware signatures, obfuscation, or real suspicious domains, the high count does not indicate actual risk.
This extension should be classified as a false positive driven by automated extraction artifacts rather than genuine security concerns.
Key Reasons
- All 133 IoC findings are XIOC property access chain garbage (o.call, h.id, b.map, etc.)
- Zero malware signatures detected despite 154 total findings
- Zero obfuscation findings
- Extension name and description are consistent with legitimate HubSpot integration
- Developer email provides attribution rather than anonymity
False Positive Considerations
- XIOC property access chain garbage (all 133 IoCs)
- Code-smell findings on basic JavaScript patterns
- No malware signatures despite high finding count
- No obfuscation or high-confidence threat indicators
Source Code Not Available
Source code is not available for this version of the extension.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
HubProspect
[email protected]
HubSpot Form Submissions Exporter
[email protected]
New Tab Magnifico
[email protected]
Ship Xanh copy sản phẩm, nhân bản shop, hiển thị % phí sàn, lượt bán tháng
[email protected]
KEYOLOGIC AUTOFILLER PRO
[email protected]
Razor Wallet
[email protected]