Firefox Add-ons Verified

Mailvelope

by Mailvelope GmbH · 23.2K users · 4.0 rating
27c9599c-85a3-524c-8e42-625e85aa0133 | v6.3.0
83/ 100
HIGH risk
+26 since v6.2.0
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (83/100) still counts them.

Analysis record

Analysed
2 weeks ago
Version
v6.3.0
Artifact
SHA256 314…6EC
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

18 detail rows

YARA Rule Matches

1 rule
SeverityRuleHitsFilesMetadata
HIGHsupply chain sourcemap appended iife 3
components/decrypt-message/decryptMessageRoot.bundle.jscomponents/editor/editorRoot.bundle.jsapp/app.bundle.js
-

Publisher Evidence

Limited evidence

Mailvelope GmbH

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

48
Noisy-finding weight
x1.00
Publisher domain
mailvelope.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
3
Portfolio

13 evidence rows available.

Finding Categories

3
Malware Signatures
1
Obfuscation
13
Network

YARA Rules Matched

1 rule(3 hits)
supply chain sourcemap appended iife

Requested Permissions

8 permissions
nativeMessaging

Exchange messages with programs outside the browser

Dangerous
*://*/*
Dangerous
identity

Access your identity and sign-in tokens

High
tabs
Medium
alarms
Low
scripting
Low
storage
Low
webNavigation
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

This extension shows no evidence of malicious behavior. The most critical security indicators are all clean: zero malware signatures matched, zero obfuscation findings, and zero suspicious IoCs (domains or IPs). The 250 total findings are almost entirely code-smell detections (236 findings), which are known false-positive patterns that trigger on standard JavaScript constructs. These code-smell rules match basic patterns like fetch calls, API key references, and crypto operations—exactly what a PGP encryption extension legitimately needs.

The 13 network findings are generic fetch and xmlhttprequest calls in component files like components/enter-password/passwordDialogRoot.bundle.js, components/key-backup/backupKeyRoot.bundle.js, and components/decrypt-message/decryptMessageRoot.bundle.js. These file paths align with expected functionality for an email encryption tool: password entry, key backup, and message decryption all require network communication with key servers and backup services. No suspicious domains appear in the findings—just standard HTTP methods in bundle files.

The single manifest finding (MANIFEST-SENSITIVE-PERM-TABS in manifest.json) flags the tabs permission as potentially sensitive. However, this permission is necessary for an email extension that encrypts and decrypts messages in Gmail, Outlook, and similar email interfaces. The extension's description confirms this purpose: protecting email conversations and attachments with PGP encryption.

Counterargument: A skeptic might point to the empty developer name field as suspicious. While anonymous publishing can indicate risk, the absence of developer attribution alone does not establish malicious intent. More importantly, the actual code behavior shows no red flags: no credential harvesting patterns, no data exfiltration to unknown domains, no browser hijacking mechanisms, and no malware signatures. The high finding count (250) is driven by code-smell rules matching legitimate JavaScript, not by actual threats. If this were truly malicious, we would expect to see malware signatures, obfuscated payloads, or suspicious network destinations—none of which appear in the evidence.

The verdict is likely_false_positive because the finding volume stems from known false-positive patterns (code-smell rules on bundled JavaScript) rather than genuine security issues.

Key Reasons

  • Zero malware signatures detected
  • Zero obfuscation findings
  • Zero suspicious IoCs (domains/IPs)
  • Network findings align with expected PGP encryption functionality
  • Code-smell findings are known false-positive patterns

False Positive Considerations

  • Code-smell rules matching standard JavaScript patterns
  • Network findings for legitimate PGP key server communication
  • Tabs permission required for email extension functionality

Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 85%.

Firefox version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
83
Change since first
+26
Change from previous
+26
Versions:
First analyzed version
6.2.0
Apr 3, 2026
Risk range
58 to 83
Across analyzed versions
Latest analyzed version
6.3.0
Jun 29, 2026
Selected version
high
Version
v6.3.0
3 months ago
Risk score
83
Findings
18
Change vs previous
+26

Pick any point on the chart to explore that version's code below.

About This Extension

➡️ Email encryption for individuals &amp; businesses Mailvelope enables PGP for a wide range of webmail services, providing secure end-to-end encryption for emails and attachments. It can be used as a free solution for private users and as an enterprise-grade tool for organizations requiring enhanced security and compliance. ➡️ Mailvelope Business – Advanced encryption for organizations For businesses and large teams, Mailvelope Business provides an encryption solution with enhanced features and premium support. In order to sign up for Mailvelope Business, visit our website after downloading the extension. Mailvelope Business is currently available for Nextcloud and Google Workspace. Mailvelope Business for Outlook on the Web is coming soon. ➡️ Mailvelope for You – Secure emails on almost any provider Mailvelope's free version enables private users to encrypt their emails on nearly all webmail providers, including Gmail, Outlook, Nextcloud, Yahoo, and many more. Through our partnerships with <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/5cff19bdb0c5a157dcbcf3f3f022cbc4794fa85e6eec5f3aeab7fc39e005f70f/http%3A//WEB.DE" rel="nofollow">WEB.DE</a>, GMX, and Posteo, Mailvelope offers deep integration into their webmail services. With an intuitive interface and seamless browser integration, Mailvelope makes OpenPGP encryption accessible to everyone. Key features: ✅ End-to-end encryption – Encrypt emails directly in your browser before they leave your outbox. Only you and your recipient can read them. ✅ Works with major webmail providers – Compatible with Gmail, Yahoo, <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/5df07da2d9f137ab21d4a4d63cb97500a3633181a2736883da16dbe5aeb56149/http%3A//Outlook.com" rel="nofollow">Outlook.com</a>, and self-hosted webmail clients like Roundcube. ✅ Mailvelope Business – Secure email encryption for businesses, ensuring compliance with strict data privacy regulations. ✅ Mailvelope key server – A managed and protected key server, simplifying PGP key distribution and verification. ✅ User-friendly &amp; seamless integration – Mailvelope integrates smoothly into your workflow, making encryption simple for everyone. ✅ Secure key management – Your private encryption keys are stored securely on your device, never exposed to third parties. ✅ GDPR &amp; compliance ready – Protect confidential business emails and meet privacy and data protection requirements. ✅ Open source &amp; transparent – Mailvelope's code is publicly available for security audits and community contributions. 🚀 Get started today: 🔗 Website: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/526ba7f64c36f46616785811aebb80b16049d1667a4cdec88933cdb03c4399ea/http%3A//mailvelope.com" rel="nofollow">mailvelope.com</a> 🔗 Source code: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/3affcb7a8c785e6603c417308720b08b349dcadbfca696e2f4f74342fa6ed6d3/http%3A//github.com/mailvelope/mailvelope" rel="nofollow">github.com/mailvelope/mailvelope</a> 🔗 Security audits: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/e3dbb461dfc6749d9a77ccd29d565f5874ed55598acce8d69bcb46e3b3270ff7/http%3A//github.com/mailvelope/mailvelope/wiki/Security" rel="nofollow">github.com/mailvelope/mailvelope/wiki/Security</a> 🔗 Follow us: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/ba7bef9e3eb8bfecf5cbc9245ba28b80e4aa48be7ae050721888e2860a8c045c/http%3A//x.com/mailvelope" rel="nofollow">x.com/mailvelope</a>

Frequently Asked Questions