Chrome Web Store Verified

randstad_poc

by [email protected] · 6 users
0a07ee28-88a7-5007-8b75-2f90e1e1e87f | v2022.6.21.1026
0/ 100
MINIMAL risk
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
9 months ago
Version
v2022.6.21.1026
Artifact
SHA256 1A2…A84
Source
Findings (non-IoC)

No Findings

All security checks passed

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

56
Noisy-finding weight
x1.00
Publisher domain
whatfix.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
34
Portfolio

12 evidence rows available.

No Threats Detected

This extension passed all security checks

AI Security Report

AI Security Review

Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-05-09. The review verdict is likely false positive with 75% confidence.

Recommended action: suppress false positive. Evidence context: threat category none; evidence quality strong.

This extension named "randstad_poc" is published by [email protected] with a description stating it provides "in-app interactive guides and walkthroughs." The network findings exclusively reference whatfix.com domains: whatfix.com/6f75c0b0-c0be-11ec-8265-000d3a1efee9/widget/widget.nocache.js (lines 2785, 2801, 3038), whatfix.com/6f75c0b0-c0be-11ec-8265-000d3a1efee9/embed/711B885AD03BD3091F7C057FE247FAF0.cache.js (line 6671), and whatfix.com/6f75c0b0-c0be-11ec-8265-000d3a1efee9/blogs/blogs.nocache.js (line 2279). These are legitimate service endpoints for the Whatfix platform, not suspicious third-party domains.

The 2796 IoC findings represent known false-positive noise from the XIOC extractor. The evidence shows zero malware signatures and zero malware findings in the findings_summary. The obfuscation findings—OBFUSCATION-LARGE_BASE64 in files like tasker/tasker.nocache.js:2688, end/end.nocache.js:2468, and deck/deck.nocache.js:2552—are typical of bundled JavaScript frameworks that embed assets as base64 strings, not malicious obfuscation. The 310 code-smell findings are classified as low-severity noise per the CVEQ false-positive patterns documentation.

The extension's unusual name "randstad_poc" suggests this is a proof-of-concept or enterprise custom build rather than a public-facing extension, which explains the minimal user count of 3. This is consistent with internal deployments of the Whatfix platform.

A skeptic might argue that the combination of obfuscation patterns and high finding counts warrants concern. However, the evidence shows no malware signatures, no suspicious external domains beyond whatfix.com, and the developer email ([email protected]) matches the network destinations. The base64 patterns in .nocache.js files are standard bundling artifacts, not steganographic hiding. Without actual malware signatures or credential-theft indicators, the high finding count is noise from known CVEQ FP patterns.

Key Reasons

  • Zero malware signatures and zero malware findings in evidence
  • All network activity targets legitimate whatfix.com domains matching developer attribution
  • High IoC count (2796) is known XIOC extractor noise with no specific suspicious domains
  • Base64 obfuscation patterns are standard bundling artifacts in .nocache.js files

False Positive Considerations

  • XIOC extractor noise generating inflated IoC counts
  • Bundled JavaScript frameworks triggering obfuscation rules on base64 assets
  • Code-smell findings from standard Node.js patterns in bundled code
  • Low user count and POC naming create false threat perception

About This Extension

Whatfix is a digital guidance and engagement platform that helps companies deliver modern and easy onboarding, effective training, and better support to users through contextual content displayed at the time of need. With Whatfix users get a personalized experience of the software application, starting from onboarding and training to continued engagement. You can use Whatfix across all web-based applications and it's available as a simple, easy-to-install browser extension. Personalized User Onboarding- Access personalized and contextual in-app content to make it simple and intuitive for you to use the software application. Walkthroughs guide you, step-by-step for the completion of activities in the system. In-App Help and Guidance- Whatfix eliminates the need for you to approach your support staff for 'how to' queries. Our help content can be personalized based on where you are in the application, to provide you with relevant information whenever you need it. On the Job Learning- Our automatically-generated multi-format content makes for more engaging and effective training compared to traditional training. Videos, pdf, slideshows can be pulled into your LMS with SCORM integration to use as a part of your learning plan.

Frequently Asked Questions