Better Search for Google
From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 4 weeks ago
- Version
- v1.1.1
- Artifact
- SHA256 234…D3C
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
9 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall persistence mechanism | 3 | content-scripts/content.jsbackground.jschunks/dashboard-CWHY9CJT.js | - |
| LOW | postinstall crypto operations | 2 | chunks/dashboard-CWHY9CJT.jsbackground.js | - |
| LOW | postinstall file manipulation | 5 | chunks/dashboard-CWHY9CJT.jssearch.htmlcontent-scripts/content.js +2 more | - |
| LOW | postinstall environment access | 1 | chunks/dashboard-CWHY9CJT.js | - |
| LOW | postinstall obfuscation | 3 | chunks/dashboard-CWHY9CJT.jsMETA-INF/manifest.mfMETA-INF/cose.manifest | - |
| LOW | postinstall network communication | 3 | chunks/dashboard-CWHY9CJT.jscontent-scripts/content.jsbackground.js | - |
| LOW | postinstall system command | 7 | assets/welcome-Y5ANY7Y0.csspopup.htmlchunks/dashboard-CWHY9CJT.js +4 more | - |
| LOW | postinstall file download | 5 | chunks/_virtual_wxt-html-plugins-DPbbfBKe.jscontent-scripts/content.jsbackground.js +2 more | - |
| LOW | NoUseWeakRandom | 1 | content-scripts/content.js | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidenceDracon
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
YARA Rules Matched
9 rules(30 hits)Requested Permissions
39 permissionsAI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
The manifest (manifest.json) declares the tabs permission, which is normal for an extension that needs to read the URL of the current Google Search page in order to apply its filtering logic. No other high‑risk permissions (such as cookies, webRequest, or proxy) are present. Two JavaScript files make network requests: chunks/_virtual_wxt-html-plugins-CdCj8_S8.js:1 and content-scripts/content.js:25 each contain a fetch call. These calls are the only active runtime behavior observed and are consistent with downloading a blocklist or updating filter rules.
The bulk of the findings are domain IoCs extracted from the code (extracted_from_files). The list includes domains such as fool.com, 3commas.io, cryptohopper.com, icobench.com, icotracker.com, icodrops.com, swcpoker.eu, coinsutra.com, and marketwatch.com. Many of these sites are legitimate news or cryptocurrency‑related sites that are commonly added to content‑farm or low‑quality‑result blocklists. The XIOC extractor is known to flag any literal string that looks like a domain, even when the string is merely part of a hard‑coded blocklist. Because the extension’s purpose is to block “content farms, spam sites, and low‑quality results,” the presence of a large static list of domains is expected and does not imply that the extension is contacting those sites for nefarious purposes.
No malware‑signature or malware findings are present, and the extension contains no obfuscation, secret extraction, or code‑smell findings that would suggest hidden payloads. The only permission request is tabs, and the network activity is limited to simple fetch calls, which aligns with a benign content‑filtering workflow.
A skeptic might argue that the many listed domains could be used to track users or that the fetch calls could exfiltrate browsing data to third‑party servers. However, the evidence shows the calls are issued from static bundle files that are typically employed to retrieve an updated blocklist; there is no indication of data being sent out from the user’s browser, nor are there any write‑to‑external‑host requests beyond the initial list download. The domains flagged as IoCs are not obscure command‑and‑control addresses; they are public sites that a filter would normally block, which strongly suggests the findings are false positives generated by the IoC extractor rather than evidence of malicious intent.
In conclusion, the extension’s behavior matches its description of improving Google Search results by blocking low‑quality sites. The high count of IoC findings stems from the blocklist content rather than malicious activity, and there is no technical evidence of credential theft, hijacking, or proxyware. Users can consider the extension safe for its intended purpose, though they should remain aware that any filter based on domain lists can occasionally block legitimate content.
Key Reasons
- Only the tabs permission is requested, which is typical for search‑filter extensions
- Network activity is limited to fetch calls in two JavaScript files, consistent with blocklist updates
- All domain findings are likely entries in a hard‑coded blocklist rather than C2 addresses
- No malware signatures, obfuscation, or credential‑related code were detected
- Extension name does not imitate any known product, eliminating impersonation concerns
False Positive Considerations
- IoC extractor flags all literal domain strings in blocklist
- High finding count due to bundled blocklist entries
Reviewed 2026-05-31; recommended action: no action; model confidence 85%.
Firefox version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace