AEM Sidekick
The AI review rates the findings as likely false positive, but the risk score (50/100) still counts them.
Analysis record
- Analysed
- 1 weeks ago
- Version
- v7.34.1
- Artifact
- SHA256 3AA…F94
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
15 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | credential env files | 5 | views/login/login.js.mapviews/json/json.js.mapproject.js +2 more | - |
| LOW | postinstall persistence mechanism | 7 | views/login/login.js.mapviews/json/json.js.mapviews/json/flow.js.map +4 more | - |
| LOW | postinstall file download | 21 | _locales/en/messages.jsonindex.js.map_locales/fr/messages.json +18 more | - |
| LOW | NoUseWeakRandom | 9 | views/login/login.jsindex.js.mapcache-buster.js +6 more | - |
| LOW | SQLInjection | 3 | views/json/json.jsindex.jsviews/login/login.js | - |
| LOW | LocalStorageShouldNotBeUsed | 7 | content.jsviews/login/login.js.mapviews/json/json.js.map +4 more | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 3 | views/login/login.js.mapviews/json/json.js.mapindex.js.map | - |
| LOW | postinstall obfuscation | 7 | views/login/login.jsviews/login/login.js.mapviews/json/json.js.map +4 more | - |
| LOW | postinstall crypto operations | 8 | views/login/login.js.map_metadata/verified_contents.jsonindex.js +5 more | - |
| LOW | postinstall file manipulation | 37 | auto-login.js_locales/fr/messages.jsonviews/json/focus-visible.js +34 more | - |
| LOW | postinstall system command | 25 | views/login/login.jsbackground.jsindex.js.map +22 more | - |
| LOW | postinstall environment access | 1 | sp-tray.js | - |
| LOW | postinstall registry modification | 4 | lib/polyfills.min.jsviews/login/login.js.mapviews/json/json.js.map +1 more | - |
| LOW | postinstall network communication | 25 | background.jsviews/login/login.jsindex.js.map +22 more | - |
| LOW | OriginsNotVerified | 1 | views/json/json.js | - |
Publisher Evidence
LowPublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
YARA Rules Matched
15 rules(163 hits)Requested Permissions
7 permissionsAI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The AEM Sidekick extension is published by Adobe ([email protected]), a well-known and trusted software vendor. This extension's stated purpose is to allow content authors to preview and publish content on Adobe Experience Manager (AEM) sites, which is a legitimate enterprise content management workflow.
All six findings in this extension are network-related calls detected in utility and view files. Specifically, fetch calls appear in utils/admin.js:109, url-cache.js:86 and :95, actions.js:544, and views/doc-source/js/ui.js:164. A socket_io call is detected in index.js:15. These network activities are entirely expected for an extension that must communicate with AEM servers to enable preview and publishing functionality. Without actual domain destinations extracted, these generic network findings represent normal operational behavior rather than suspicious data exfiltration.
Critically, the findings summary shows zero malware signatures, zero suspicious domain IoCs, zero obfuscation indicators, and zero code-smell findings. The absence of any malware-family matches or suspicious domain extraction is a strong signal of benign behavior. The extension has no obfuscation patterns that would suggest an attempt to hide malicious code.
The strongest counterargument to this verdict would be that network activity alone could indicate data exfiltration. However, this argument fails because: (1) the extension is from a verified Adobe email address, not an anonymous publisher; (2) the extension's documented purpose explicitly requires server communication for its core functionality; (3) no suspicious domains were extracted from these network calls; and (4) there are no corroborating findings like obfuscation or malware signatures that typically accompany malicious exfiltration. For a content management tool, network activity is not just expected—it's essential to the product's function.
This extension represents a clear case of automated analysis flags on legitimate enterprise software. The network findings are functional necessities for AEM Sidekick's preview and publish capabilities, not indicators of compromise.
Key Reasons
- Verified Adobe publisher ([email protected])
- Zero malware signatures detected
- Zero suspicious domain IoCs extracted
- Network findings match documented extension functionality
- No obfuscation or code-smell indicators
False Positive Considerations
- Generic network call detection on legitimate enterprise tool
- Socket.io library usage flagged as network finding
Reviewed 2026-05-25; recommended action: suppress false positive; model confidence 95%.
Chrome version history
Risk trend by version
13 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Adobe Acrobat: PDF edit, convert, sign tools
[email protected]
Adobe Experience Platform Debugger
[email protected]
Adobe Experience Cloud Visual Editing Helper
[email protected]
Adobe Photoshop
[email protected]
Adobe Workfront review tool
[email protected]
Activity Map v4
[email protected]