Grammarly: AI Writing Assistant and Grammar Checker App
Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- Today
- Version
- v14.1334.0
- Artifact
- SHA256 A3A…CEE
- Source
- Findings (non-IoC)
No Findings
All security checks passed
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
No Threats Detected
This extension passed all security checks
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
This extension is the official Grammarly writing assistant from a verified developer ([email protected]) with 39 million users. The security findings detected are entirely consistent with legitimate extension behavior and known false-positive patterns.
The single manifest finding flags the 'tabs' permission in manifest.json. This permission is necessary and expected for a grammar checker that needs to analyze text across web pages. Grammarly must read page content to provide real-time writing suggestions, making this permission functionally required rather than suspicious.
All six network findings originate from bundled vendor code in webpack chunks (src/js/8581.vendors.chunk.js, src/js/2887.vendors.chunk.js, src/js/1044.vendors.chunk.js, src/js/1974.vendors.chunk.js) and WebSocket transport files (src/inkwell/assets/CAPIWebSocketTransport-DztTrDg1-8WOYftOV.js, src/inkwell/assets/CAPIWebSocketTransport-DztTrDg1-DSQiisKE.js). These files contain third-party dependencies and communication infrastructure. The findings detect standard network operations—fetch calls, jQuery AJAX requests, and WebSocket connections—which are how any modern web application communicates with backend services. No specific suspicious domains were extracted from these network calls.
Critically, the analysis found zero malware signatures, zero obfuscation indicators, zero code-smell findings, and zero extracted indicators of compromise (IoCs). The absence of these high-confidence threat signals is significant. Real malicious extensions typically exhibit at least one of: malware signatures in code, obfuscation techniques, suspicious domain connections, or credential theft patterns. None of these are present here.
Strongest Counterargument: A skeptic might argue that 39 million users doesn't guarantee safety—malicious extensions can gain large followings before detection, and the 'tabs' permission could theoretically enable data exfiltration. However, this counterargument fails because: (1) Grammarly is a publicly traded company with a 15+ year reputation, making supply-chain compromise extremely unlikely compared to anonymous publishers; (2) the 'tabs' permission alone doesn't indicate malice—password managers, ad blockers, and productivity tools all legitimately require it; (3) there is zero evidence of suspicious behavior in the actual code—no hidden domains, no obfuscation, no credential handling outside expected patterns. Without specific malicious indicators, the permission is benign in this context.
The findings represent normal operation of a complex web application with bundled dependencies. This extension should be classified as a false positive.
Key Reasons
- Verified publisher (Grammarly) with 39M users and legitimate developer email
- Zero malware signatures, obfuscation, or suspicious IoCs detected
- Network findings in bundled vendor code are expected behavior
- 'tabs' permission is functionally necessary for grammar checking
False Positive Considerations
- Network findings in webpack vendor chunk files (bundled dependencies)
- Sensitive 'tabs' permission required for legitimate functionality
- High finding count from bundled code, not malicious behavior
Reviewed 2026-06-10; recommended action: suppress false positive; model confidence 95%.
Chrome version history
Risk trend by version
3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Superhuman Go: AI Assistant
[email protected]
Edge Translate - Browser Translator | PDF Translation | MV3 | Open Source
[email protected]
Intelbras Cloud
[email protected]
SlingPlayer for DISH Anywhere
Unknown Developer
My Jobscore
[email protected]
种草星球-TikTok爆单神器,商品自动提报采集邀评【永久免费】
[email protected]