Firefox Add-ons

JSaw Puzzle

by Raymond Hill · 81 users · 5.0 rating
07c3711f-b24c-5474-bfe1-885b90573704 | v1.12
44/ 100
MEDIUM risk
-13 since v1.11
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (44/100) still counts them.

Analysis record

Analysed
2 weeks ago
Version
v1.12
Artifact
SHA256 943…9DD
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

4 detail rows

Publisher Evidence

Limited evidence

Raymond Hill

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

34
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Limited signal
Limited
Extension portfolio
5
Portfolio

12 evidence rows available.

Finding Categories

4
Network

Requested Permissions

4 permissions
contextMenus
Low
storage
Low
https://commons.wikimedia.org/*
Low
https://*.publicdomainpictures.net/*
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The JSaw Puzzle extension generates 42 total findings, but analysis reveals these are entirely consistent with documented false-positive patterns. All 8 malware-signature findings trigger postinstall_* YARA rules (e.g., YARA--postinstall_network_communication in _locales/en/messages.json, YARA--postinstall_file_download in audio/claps/35104_m1rk0_applause_8sec.mp3, YARA--postinstall_obfuscation in jsawpuzzle-ui.js). Per CVEQ guidelines, postinstall_* rules match basic Node.js patterns like fetch, exec, and crypto operations and are classified as code-smell noise that should never drive a verdict.

The 4 network findings are all legitimate fetch calls to public domain image sources: feeds/publicdomainpictures.js:35, feeds/wikimedia-commons-potd.js:55, feeds/wikimedia-commons-featured.js:35, and feeds/wikimedia-commons-fetch.js:47. These align with the extension's stated purpose of creating jigsaw puzzles from images. No suspicious domains, credential access, or data exfiltration endpoints appear in the evidence.

The findings_summary confirms 38 code-smell findings and 0 actual malware signatures, 0 obfuscation detections, and 0 IoCs. The findings_summary explicitly shows "malware-signature":"0" and "obfuscation":"0" in the threat_indicators field, meaning the 8 malware-signature entries are misclassified code-smell detections.

Counterargument: A skeptic might argue that 38 high-severity findings warrants concern regardless of rule type. However, the CVEQ guidelines explicitly state that postinstall_* rules are well-documented noise sources that fire on almost any non-trivial JavaScript. The severity labels on these findings do not reflect actual risk—the nature of the detections matters, not their count or severity classification. With zero actual malware signatures, zero obfuscation, and network calls only to Wikimedia Commons and publicdomainpictures (legitimate image sources), there is no evidence of malicious behavior. The extension fetches images for puzzle creation, which matches its description.

The anonymous developer and low user count (63) are neutral signals that don't override the absence of actual threat indicators.

Key Reasons

  • All malware-signature findings are postinstall_* code-smell rules documented as false positives
  • Zero actual malware signatures or obfuscation detected in threat_indicators
  • Network calls only to legitimate public domain image sources
  • Extension behavior matches stated purpose (jigsaw puzzle creation)

False Positive Considerations

  • postinstall_* YARA rules matching basic Node.js patterns
  • Code-smell findings (38 total) misclassified as high-severity malware-signature
  • Network findings to legitimate image sources (Wikimedia Commons)

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.

Firefox version history

Risk trend by version

4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
44
Change since first
-7
Change from previous
-13
Versions:
First analyzed version
1.8
Jan 19, 2026
Risk range
44 to 56
Across analyzed versions
Latest analyzed version
1.12
Sep 16, 2026
Selected version
medium
Version
v1.12
2 weeks ago
Risk score
44
Findings
4
Change vs previous
-13

Pick any point on the chart to explore that version's code below.

About This Extension

A browser extension to create and solve jigsaw puzzles. The extension can fetch random pictures from different feeds. Currently it can fetch from Wikimedia Commons[1] and Public Domain Pictures[2]. Important: Firefox version 126.0 and below requires that you explicitly grant permissions to be able fetch pictures from the remote servers. For more details, see README at: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/0075c11a1d5e9bf145e7c3580d87b22b29888858656a4611df71de648d54a0b9/https%3A//github.com/gorhill/jsawpuzzle%23jsaw-puzzle" rel="nofollow">https://github.com/gorhill/jsawpuzzle#jsaw-puzzle</a> [1] <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/dab7fae3e7111faf2b27cadcb5ab9e08cb7c1dac50d44fdf638b2bbdbc83aea9/https%3A//commons.wikimedia.org/" rel="nofollow">https://commons.wikimedia.org/</a> [2] <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/9430cc0c42d3924b687d3650b4601cddabf91e4a4706a9156aae86478b79472b/https%3A//www.publicdomainpictures.net/" rel="nofollow">https://www.publicdomainpictures.net/</a>

Frequently Asked Questions