Chrome Web Store Verified

AEM Sidekick

by [email protected] · 10.0K users · 4.6 rating
34aa67e2-b169-5f2d-97bb-e6945e8c6ccd | v7.34.1
50/ 100
MEDIUM risk
No change since v7.34.0
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (50/100) still counts them.

Analysis record

Analysed
1 weeks ago
Version
v7.34.1
Artifact
SHA256 3AA…F94
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

171 detail rows

YARA Rule Matches

15 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall obfuscation 7
views/json/json.js.mapviews/json/json.jsindex.js +4 more
-
LOWpostinstall crypto operations 8
views/json/json.jsindex.js.mapviews/login/login.js.map +5 more
-
LOWpostinstall file manipulation 37
auto-login.jsviews/json/focus-visible.js.mapui.js +34 more
-
LOWpostinstall system command 25
_locales/pt_BR/messages.jsonbackground.jsurl-cache.js +22 more
-
LOWpostinstall environment access 1
sp-tray.js
-
LOWpostinstall registry modification 4
lib/polyfills.min.jsindex.js.mapviews/login/login.js.map +1 more
-
LOWpostinstall network communication 25
background.jsurl-cache.jsproject.js +22 more
-
LOWOriginsNotVerified 1
views/json/json.js
-
LOWcredential env files 5
index.jsindex.js.mapviews/login/login.js.map +2 more
-
LOWpostinstall persistence mechanism 7
views/json/json.jsindex.jsviews/login/login.js +4 more
-
LOWpostinstall file download 21
_locales/en/messages.jsonurl-cache.jsutils/rum.js +18 more
-
LOWNoUseWeakRandom 9
views/json/json.js.maputils/rum.jsauth.js +6 more
-
LOWSQLInjection 3
views/json/json.jsindex.jsviews/login/login.js
-
LOWLocalStorageShouldNotBeUsed 7
content.jsviews/json/json.jsindex.js +4 more
-
LOWDebuggerStatementsShouldNotBeUsed 3
index.js.mapviews/login/login.js.mapviews/json/json.js.map
-

Publisher Evidence

Low

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

79
Noisy-finding weight
x1.00
Publisher domain
adobe.com
Trusted match
Store verification signal
Limited signal
Limited
Extension portfolio
25
Portfolio

12 evidence rows available.

Finding Categories

8
Network

YARA Rules Matched

15 rules(163 hits)
postinstall obfuscation postinstall crypto operations postinstall file manipulation postinstall system command postinstall environment access postinstall registry modification postinstall network communication OriginsNotVerified credential env files postinstall persistence mechanism postinstall file download NoUseWeakRandom SQLInjection LocalStorageShouldNotBeUsed DebuggerStatementsShouldNotBeUsed

Requested Permissions

7 permissions
https://*/*
Dangerous
activeTab
Medium
contextMenus
Low
declarativeNetRequest
Low
scripting
Low
storage
Low
http://localhost:3000/*
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The AEM Sidekick extension is published by Adobe ([email protected]), a well-known and trusted software vendor. This extension's stated purpose is to allow content authors to preview and publish content on Adobe Experience Manager (AEM) sites, which is a legitimate enterprise content management workflow.

All six findings in this extension are network-related calls detected in utility and view files. Specifically, fetch calls appear in utils/admin.js:109, url-cache.js:86 and :95, actions.js:544, and views/doc-source/js/ui.js:164. A socket_io call is detected in index.js:15. These network activities are entirely expected for an extension that must communicate with AEM servers to enable preview and publishing functionality. Without actual domain destinations extracted, these generic network findings represent normal operational behavior rather than suspicious data exfiltration.

Critically, the findings summary shows zero malware signatures, zero suspicious domain IoCs, zero obfuscation indicators, and zero code-smell findings. The absence of any malware-family matches or suspicious domain extraction is a strong signal of benign behavior. The extension has no obfuscation patterns that would suggest an attempt to hide malicious code.

The strongest counterargument to this verdict would be that network activity alone could indicate data exfiltration. However, this argument fails because: (1) the extension is from a verified Adobe email address, not an anonymous publisher; (2) the extension's documented purpose explicitly requires server communication for its core functionality; (3) no suspicious domains were extracted from these network calls; and (4) there are no corroborating findings like obfuscation or malware signatures that typically accompany malicious exfiltration. For a content management tool, network activity is not just expected—it's essential to the product's function.

This extension represents a clear case of automated analysis flags on legitimate enterprise software. The network findings are functional necessities for AEM Sidekick's preview and publish capabilities, not indicators of compromise.

Key Reasons

  • Verified Adobe publisher ([email protected])
  • Zero malware signatures detected
  • Zero suspicious domain IoCs extracted
  • Network findings match documented extension functionality
  • No obfuscation or code-smell indicators

False Positive Considerations

  • Generic network call detection on legitimate enterprise tool
  • Socket.io library usage flagged as network finding

Reviewed 2026-05-25; recommended action: suppress false positive; model confidence 95%.

Chrome version history

Risk trend by version

13 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
50
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
7.27.3
Jan 21, 2026
Risk range
44 to 50
Across analyzed versions
Latest analyzed version
7.34.1
Sep 22, 2026
Selected version
medium
Version
v7.34.1
1 weeks ago
Risk score
50
Findings
171
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Edit, preview, and publish your AEM content simply and in-context using AEM Sidekick: • Jump to the editor from a published page to quickly make content changes • Switch between configured environments • Update the preview to see the latest content • Publish your changes Terms of use: https://www.adobe.com/legal/licenses-terms.html

Frequently Asked Questions