Chrome Web Store

webcode bridge

by [email protected] · 187 users · 4.0 rating
0581eb7b-12bd-57cd-9f15-ad8d586d79ed | v1.2.0
52/ 100
MEDIUM risk
No change since v1.0.1
Risk verdict
Review before use

Score-based assessment (medium risk, 52/100). No analyst review available.

Analysis record

Analysed
1 weeks ago
Version
v1.2.0
Artifact
SHA256 CCD…E83
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

52 detail rows

YARA Rule Matches

10 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall crypto operations 4
_metadata/verified_contents.jsonassets/chunk-CtCStRN6.jsgenerated/network_capture_main.js +1 more
-
LOWpostinstall system command 8
assets/chunk-DKb7HYjw.jsassets/chunk-DmYPLU_4.jsassets/chunk-D7Ff9fQP.js +5 more
-
LOWpostinstall file manipulation 7
assets/chunk-DmYPLU_4.jsassets/popup-7SSDzIkG.jsgenerated/network_capture_main.js +4 more
-
LOWpostinstall network communication 11
generated/network_capture_main.jsassets/offscreen-CmVp0XX2.jsassets/chunk-Cck41Ip0.js +8 more
-
LOWpostinstall environment access 3
assets/chunk-D3v-lrKq.jsassets/chunk-DKb7HYjw.jsassets/chunk-DmYPLU_4.js
-
LOWpostinstall registry modification 1
assets/chunk-CtCStRN6.js
-
LOWpostinstall obfuscation 4
generated/network_capture_main.jsassets/chunk-Cck41Ip0.jsassets/chunk-CtCStRN6.js +1 more
-
LOWpostinstall file download 6
assets/chunk-B5Qt9EMX.jsassets/chunk-DmYPLU_4.jsassets/chunk-D7Ff9fQP.js +3 more
-
LOWNoUseWeakRandom 4
assets/chunk-DmYPLU_4.jsgenerated/network_capture_main.jsassets/chunk-Cck41Ip0.js +1 more
-
LOWpostinstall persistence mechanism 1
assets/chunk-DmYPLU_4.js
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

4 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

29
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Limited signal
Limited
Extension portfolio
3
Portfolio

12 evidence rows available.

Finding Categories

3
Network
4
IoC Indicators

YARA Rules Matched

10 rules(49 hits)
postinstall crypto operations postinstall system command postinstall file manipulation postinstall network communication postinstall environment access postinstall registry modification postinstall obfuscation postinstall file download NoUseWeakRandom postinstall persistence mechanism

Requested Permissions

7 permissions
<all_urls>

Access and modify data on every website you visit

Dangerous
storage
Low
notifications
Low
offscreen
Low
alarms
Low
http://127.0.0.1/*
Low
http://localhost/*
Low

Security Analysis Summary

Security Analysis Overview

webcode bridge is a Chrome Web Store extension published by [email protected]. Version 1.2.0 has been analyzed by the Risky Plugins security platform, receiving a risk score of 52.26/100 (MEDIUM risk) based on 56 security findings.

Risk Assessment

This extension presents moderate security risk. Several findings were detected that may warrant attention. Users should carefully review the permissions and findings before installation.

Findings Breakdown

  • Medium: 7 finding(s)
  • Low: 49 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

webcode bridge is published by [email protected] on the Chrome Web Store marketplace. The extension has approximately 187 users.

Recommendation

Exercise caution with this extension. Review the detailed findings and ensure the requested permissions align with the extension's stated functionality before installation.

Chrome version history

Risk trend by version

8 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
52
Change since first
-3
Change from previous
No change
Versions:
First analyzed version
0.5.2
Mar 31, 2026
Risk range
47 to 58
Across analyzed versions
Latest analyzed version
1.2.0
Sep 11, 2026
Selected version
medium
Version
v1.2.0
1 weeks ago
Risk score
52
Findings
56
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

webcode bridge (Browser Extension) Project: https://github.com/three-water666/webcode IMPORTANT This extension is a companion for webcode gateway. You must install and start the webcode gateway extension in VS Code before using this. For most users, the recommended Edge Isolated Keepalive mode auto-loads this bridge from the VS Code extension, so manual browser-extension installation is not required. Introduction webcode bridge is the connector that links Web AI Chatbots (Gemini, ChatGPT, DeepSeek, etc.) to your local VS Code environment. It intercepts specific AI tool calls and securely forwards them to your local VS Code server, allowing the cloud AI to "see" and "operate" on your local projects. Usage Recommended Launch: Open a folder in VS Code, start webcode gateway from the status bar, and choose an AI site. The default Edge Isolated Keepalive mode loads this bridge automatically. Manual Browser Modes: If you use regular Chrome/Edge, the system default browser, or user-profile keepalive mode, install this browser extension manually first. Auto Connect: Open Gemini or other supported AI pages from webcode. The extension will automatically detect and connect to the local service (the icon will turn green). Start Chatting: Open a new chat, type your actual request first, then add /webcode or @webcode at the end of the same message. When webcode asks whether to add the initialization prompt, choose Add or press Enter. webcode replaces the trigger word with the initialization prompt, then you can review and send the message yourself. Troubleshooting: If the icon is red or gray, click the icon to view detailed troubleshooting steps. Get VS Code Extension Search in VS Code Marketplace: webcode gateway License MIT License

Frequently Asked Questions