JSaw Puzzle
The AI review rates the findings as likely false positive, but the risk score (44/100) still counts them.
Analysis record
- Analysed
- 2 weeks ago
- Version
- v1.12
- Artifact
- SHA256 943…9DD
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
Limited evidenceRaymond Hill
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
Requested Permissions
4 permissionsAI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The JSaw Puzzle extension generates 42 total findings, but analysis reveals these are entirely consistent with documented false-positive patterns. All 8 malware-signature findings trigger postinstall_* YARA rules (e.g., YARA--postinstall_network_communication in _locales/en/messages.json, YARA--postinstall_file_download in audio/claps/35104_m1rk0_applause_8sec.mp3, YARA--postinstall_obfuscation in jsawpuzzle-ui.js). Per CVEQ guidelines, postinstall_* rules match basic Node.js patterns like fetch, exec, and crypto operations and are classified as code-smell noise that should never drive a verdict.
The 4 network findings are all legitimate fetch calls to public domain image sources: feeds/publicdomainpictures.js:35, feeds/wikimedia-commons-potd.js:55, feeds/wikimedia-commons-featured.js:35, and feeds/wikimedia-commons-fetch.js:47. These align with the extension's stated purpose of creating jigsaw puzzles from images. No suspicious domains, credential access, or data exfiltration endpoints appear in the evidence.
The findings_summary confirms 38 code-smell findings and 0 actual malware signatures, 0 obfuscation detections, and 0 IoCs. The findings_summary explicitly shows "malware-signature":"0" and "obfuscation":"0" in the threat_indicators field, meaning the 8 malware-signature entries are misclassified code-smell detections.
Counterargument: A skeptic might argue that 38 high-severity findings warrants concern regardless of rule type. However, the CVEQ guidelines explicitly state that postinstall_* rules are well-documented noise sources that fire on almost any non-trivial JavaScript. The severity labels on these findings do not reflect actual risk—the nature of the detections matters, not their count or severity classification. With zero actual malware signatures, zero obfuscation, and network calls only to Wikimedia Commons and publicdomainpictures (legitimate image sources), there is no evidence of malicious behavior. The extension fetches images for puzzle creation, which matches its description.
The anonymous developer and low user count (63) are neutral signals that don't override the absence of actual threat indicators.
Key Reasons
- All malware-signature findings are postinstall_* code-smell rules documented as false positives
- Zero actual malware signatures or obfuscation detected in threat_indicators
- Network calls only to legitimate public domain image sources
- Extension behavior matches stated purpose (jigsaw puzzle creation)
False Positive Considerations
- postinstall_* YARA rules matching basic Node.js patterns
- Code-smell findings (38 total) misclassified as high-severity malware-signature
- Network findings to legitimate image sources (Wikimedia Commons)
Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.
Firefox version history
Risk trend by version
4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
uBlock Origin Lite
Raymond Hill
uBlock Origin
Raymond Hill
uBO-Scope
Raymond Hill
VaultysHub extension
Vaultys
Kindredly - A safer, private web for families
Kindredly.ai
Malwarebytes Browser Guard
Malwarebytes