Mailvelope
The AI review rates the findings as likely false positive, but the risk score (83/100) still counts them.
Analysis record
- Analysed
- 2 weeks ago
- Version
- v6.3.0
- Artifact
- SHA256 314…6EC
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
1 rule| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | supply chain sourcemap appended iife | 3 | components/decrypt-message/decryptMessageRoot.bundle.jscomponents/editor/editorRoot.bundle.jsapp/app.bundle.js | - |
Publisher Evidence
Limited evidenceMailvelope GmbH
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
YARA Rules Matched
1 rule(3 hits)Requested Permissions
8 permissionsExchange messages with programs outside the browser
Access your identity and sign-in tokens
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
This extension shows no evidence of malicious behavior. The most critical security indicators are all clean: zero malware signatures matched, zero obfuscation findings, and zero suspicious IoCs (domains or IPs). The 250 total findings are almost entirely code-smell detections (236 findings), which are known false-positive patterns that trigger on standard JavaScript constructs. These code-smell rules match basic patterns like fetch calls, API key references, and crypto operations—exactly what a PGP encryption extension legitimately needs.
The 13 network findings are generic fetch and xmlhttprequest calls in component files like components/enter-password/passwordDialogRoot.bundle.js, components/key-backup/backupKeyRoot.bundle.js, and components/decrypt-message/decryptMessageRoot.bundle.js. These file paths align with expected functionality for an email encryption tool: password entry, key backup, and message decryption all require network communication with key servers and backup services. No suspicious domains appear in the findings—just standard HTTP methods in bundle files.
The single manifest finding (MANIFEST-SENSITIVE-PERM-TABS in manifest.json) flags the tabs permission as potentially sensitive. However, this permission is necessary for an email extension that encrypts and decrypts messages in Gmail, Outlook, and similar email interfaces. The extension's description confirms this purpose: protecting email conversations and attachments with PGP encryption.
Counterargument: A skeptic might point to the empty developer name field as suspicious. While anonymous publishing can indicate risk, the absence of developer attribution alone does not establish malicious intent. More importantly, the actual code behavior shows no red flags: no credential harvesting patterns, no data exfiltration to unknown domains, no browser hijacking mechanisms, and no malware signatures. The high finding count (250) is driven by code-smell rules matching legitimate JavaScript, not by actual threats. If this were truly malicious, we would expect to see malware signatures, obfuscated payloads, or suspicious network destinations—none of which appear in the evidence.
The verdict is likely_false_positive because the finding volume stems from known false-positive patterns (code-smell rules on bundled JavaScript) rather than genuine security issues.
Key Reasons
- Zero malware signatures detected
- Zero obfuscation findings
- Zero suspicious IoCs (domains/IPs)
- Network findings align with expected PGP encryption functionality
- Code-smell findings are known false-positive patterns
False Positive Considerations
- Code-smell rules matching standard JavaScript patterns
- Network findings for legitimate PGP key server communication
- Tabs permission required for email extension functionality
Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 85%.
Firefox version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Mailvelope - Secure your email with PGP
Mailvelope
VaultysHub extension
Vaultys
Kindredly - A safer, private web for families
Kindredly.ai
Malwarebytes Browser Guard
Malwarebytes
VHS - Dev Tools
Vihat Software
Ultimate New Tab Page - AI Search & Dial
Dracon