Chrome Web Store Verified

BI_POC

237f6cc7-859b-5421-8135-ad2d38b13221 | v2025.3.26.1242
0/ 100
MINIMAL risk
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
9 months ago
Version
v2025.3.26.1242
Artifact
SHA256 9A6…DDD
Source
Findings (non-IoC)

No Findings

All security checks passed

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

52
Noisy-finding weight
x1.00
Publisher domain
whatfix.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
34
Portfolio

12 evidence rows available.

No Threats Detected

This extension passed all security checks

AI Security Report

AI Security Review

Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-04-30. The review verdict is likely false positive with 75% confidence.

Recommended action: suppress false positive. Evidence context: threat category none; evidence quality moderate.

This extension demonstrates characteristics of a legitimate enterprise tool with findings driven by known false positive patterns rather than malicious behavior.

The developer is identified as "[email protected]", which corresponds to Whatfix, a known digital adoption platform company. The extension description "BI POC extension for Successfactors" indicates a business intelligence proof of concept for SAP SuccessFactors integration, a legitimate enterprise use case.

All 27 network findings connect exclusively to whatfix.com, the developer's own domain. For example, NET-FETCH-whatfix.com/8efcc575-9edf-46e7-9cfc-d808e4f7bdbb/workflowengine/workflowengine.nocache.js-45878 and NET-XMLHTTPREQUEST-extension.background/extension.background.nocache.js-999 show standard extension background and workflow engine communication. No third-party or suspicious domains appear in the network findings.

The 9 obfuscation findings occur in .nocache.js files, which are characteristic of bundled/minified JavaScript from build processes. The OBFUSCATION-LARGE_BASE64-extension.foreground/extension.foreground.nocache.js-701 and OBFUSCATION-FROMCHARCODE_BULK-whatfix.com/8efcc575-9edf-46e7-9cfc-d808e4f7bdbb/workflowengine/workflowengine.nocache.js-41337 findings are consistent with webpack or similar bundler output, not malicious obfuscation.

The 3458 IoC findings represent the XIOC extractor's known false positive volume. Without specific suspicious domains in the evidence (only whatfix.com appears), this count is noise rather than evidence of malicious infrastructure.

The 0 malware signatures and 0 malware findings are the strongest indicators of benign behavior. The 367 code-smell findings are expected noise from YARA rules that fire on almost any non-trivial JavaScript.

Counterargument: A skeptic might argue the 0 user count indicates this is an untested or malicious extension that hasn't gained traction. However, the extension name "BI_POC" explicitly indicates this is a proof of concept, which may be deployed internally or to a limited audience before public release. The identifiable developer and clean network traffic to their own domain outweigh the user count concern. If this were a malicious extension, it would show malware signatures, suspicious third-party domains, or anonymous publication, none of which appear in the evidence.

Key Reasons

  • No malware signatures or malware findings in 3861 total findings
  • All network traffic goes to developer's own domain (whatfix.com)
  • Identifiable developer ([email protected]) from known company
  • Obfuscation patterns consistent with bundled/minified code in .nocache.js files
  • High IoC count is known XIOC extractor false positive pattern

False Positive Considerations

  • XIOC extractor volume (3458 IoCs without suspicious domains)
  • Code-smell YARA rules (367 findings on standard JS patterns)
  • Obfuscation in bundled .nocache.js files from build process
  • Minified/bundled JavaScript triggering false obfuscation matches

About This Extension

Whatfix is a digital guidance and engagement platform that helps companies deliver modern and easy onboarding, effective training, and better support to users through contextual content displayed at the time of need. With Whatfix users get a personalized experience of the software application, starting from onboarding and training to continued engagement. You can use Whatfix across all web-based applications and it's available as a simple, easy-to-install browser extension. Personalized User Onboarding: Access personalized and contextual in-app content to make it simple and intuitive for you to use the software application. Walkthroughs guide you, step-by-step for the completion of activities in the system. In-App Help and Guidance: Whatfix eliminates the need for you to approach your support staff for 'how to' queries. Our help content can be personalized based on where you are in the application, to provide you with relevant information whenever you need it. On the Job Learning: Our automatically-generated multi-format content makes for more engaging and effective training compared to traditional training. Videos, pdf, slideshows can be pulled into your LMS with SCORM integration to use as a part of your learning plan.

Frequently Asked Questions