Mailvelope - Secure your email with PGP
The AI review rates the findings as likely false positive, but the risk score (61/100) still counts them.
Analysis record
- Analysed
- 3 months ago
- Version
- v6.3.0
- Artifact
- SHA256 48A…45D
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidenceMailvelope GmbH
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
Extension Overview
This is Mailvelope, a well-established PGP email encryption extension published by Mailvelope GmbH. The extension description states it provides "PGP and end-to-end encryption" for Gmail, Nextcloud, Outlook, and other email platforms. Mailvelope GmbH is a known, legitimate company that has been operating for years.
Finding Analysis
The IoC findings (2221 total) are entirely benign GitHub URLs pointing to individual contributors: https://github.com/twodcube, https://github.com/eduardopsll, https://github.com/pshpak, https://github.com/watsongm24, and https://github.com/giofilo. These are developer attribution references common in open-source projects, not malicious domains. The XIOC extractor frequently misclassifies GitHub contributor URLs as suspicious indicators.
The network findings (13 total) show standard fetch and XMLHttpRequest calls in bundle files: components/enter-password/passwordDialogRoot.bundle.js:755, background.bundle.js:441, components/import-key/importKeyRoot.bundle.js:755, and components/editor/editorRoot.bundle.js:14710. These are legitimate network operations expected from an email encryption extension that needs to fetch keys, authenticate users, and communicate with PGP services. No suspicious or unknown domains appear in these network calls.
The 234 malware-signature findings with zero actual malware findings (malware: 0) indicates these are false positives from bundled npm dependencies. Webpack bundles contain hundreds of npm packages, each triggering their own YARA matches. This is a well-documented false positive pattern for legitimate extensions with bundled code.
Counterargument
A skeptic might argue the 234 malware-signature findings and "unknown" version are concerning. However, malware-signature findings in bundle files from a known publisher are classified as noise in the CVEQ system. The distinction between malware-signature (pattern matches in bundled code) and malware (confirmed malicious behavior) is critical—this extension has zero malware findings. The "unknown" version is likely a data collection artifact rather than a security issue, as Mailvelope is a well-documented, actively maintained project.
Conclusion
All findings are consistent with a legitimate, well-maintained extension from a known publisher. The high finding counts stem from known false positive patterns: GitHub contributor URLs in IoCs and bundled dependencies triggering malware-signature matches. No evidence of malicious behavior exists.
Key Reasons
- Mailvelope GmbH is a known, legitimate publisher
- IoC findings are GitHub contributor URLs, not malicious domains
- Network findings show standard fetch calls in bundle files with no suspicious domains
- 234 malware-signature findings with zero malware findings indicates bundled dependency false positives
- Extension functionality matches its stated purpose (PGP email encryption)
False Positive Considerations
- GitHub contributor URLs misclassified as IoCs
- Bundled npm packages triggering malware-signature matches
- Webpack bundle files containing standard network operations
Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 80%.
Edge version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace