Microsoft Edge Add-ons Verified

Mailvelope - Secure your email with PGP

54cb9987-31d3-59a5-a39d-dff61adf16a9 | v6.3.0
61/ 100
MEDIUM risk
-4 since v6.2.1
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (61/100) still counts them.

Analysis record

Analysed
3 months ago
Version
v6.3.0
Artifact
SHA256 48A…45D
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

157 detail rows
Showing 25 of 157 · highest severity first

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

1,059 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

Mailvelope GmbH

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

38
Noisy-finding weight
x1.00
Publisher domain
mailvelope.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
3
Portfolio

13 evidence rows available.

Finding Categories

1
Obfuscation
13
Network
1,059
IoC Indicators

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Extension Overview

This is Mailvelope, a well-established PGP email encryption extension published by Mailvelope GmbH. The extension description states it provides "PGP and end-to-end encryption" for Gmail, Nextcloud, Outlook, and other email platforms. Mailvelope GmbH is a known, legitimate company that has been operating for years.

Finding Analysis

The IoC findings (2221 total) are entirely benign GitHub URLs pointing to individual contributors: https://github.com/twodcube, https://github.com/eduardopsll, https://github.com/pshpak, https://github.com/watsongm24, and https://github.com/giofilo. These are developer attribution references common in open-source projects, not malicious domains. The XIOC extractor frequently misclassifies GitHub contributor URLs as suspicious indicators.

The network findings (13 total) show standard fetch and XMLHttpRequest calls in bundle files: components/enter-password/passwordDialogRoot.bundle.js:755, background.bundle.js:441, components/import-key/importKeyRoot.bundle.js:755, and components/editor/editorRoot.bundle.js:14710. These are legitimate network operations expected from an email encryption extension that needs to fetch keys, authenticate users, and communicate with PGP services. No suspicious or unknown domains appear in these network calls.

The 234 malware-signature findings with zero actual malware findings (malware: 0) indicates these are false positives from bundled npm dependencies. Webpack bundles contain hundreds of npm packages, each triggering their own YARA matches. This is a well-documented false positive pattern for legitimate extensions with bundled code.

Counterargument

A skeptic might argue the 234 malware-signature findings and "unknown" version are concerning. However, malware-signature findings in bundle files from a known publisher are classified as noise in the CVEQ system. The distinction between malware-signature (pattern matches in bundled code) and malware (confirmed malicious behavior) is critical—this extension has zero malware findings. The "unknown" version is likely a data collection artifact rather than a security issue, as Mailvelope is a well-documented, actively maintained project.

Conclusion

All findings are consistent with a legitimate, well-maintained extension from a known publisher. The high finding counts stem from known false positive patterns: GitHub contributor URLs in IoCs and bundled dependencies triggering malware-signature matches. No evidence of malicious behavior exists.

Key Reasons

  • Mailvelope GmbH is a known, legitimate publisher
  • IoC findings are GitHub contributor URLs, not malicious domains
  • Network findings show standard fetch calls in bundle files with no suspicious domains
  • 234 malware-signature findings with zero malware findings indicates bundled dependency false positives
  • Extension functionality matches its stated purpose (PGP email encryption)

False Positive Considerations

  • GitHub contributor URLs misclassified as IoCs
  • Bundled npm packages triggering malware-signature matches
  • Webpack bundle files containing standard network operations

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 80%.

Edge version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
61
Change since first
-4
Change from previous
-4
Versions:
First analyzed version
6.2.1
Apr 4, 2026
Risk range
61 to 65
Across analyzed versions
Latest analyzed version
6.3.0
Jun 20, 2026
Selected version
medium
Version
v6.3.0
3 months ago
Risk score
61
Findings
1217
Change vs previous
-4

Pick any point on the chart to explore that version's code below.

Frequently Asked Questions