Chrome Web Store Verified

OMICall

by [email protected] · 841 users · 5.0 rating
58fcf100-6452-5224-a9bd-a88300caa570 | v2.0.39
44/ 100
MEDIUM risk
No change since v2.0.38
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (44/100) still counts them.

Analysis record

Analysed
4 months ago
Version
v2.0.39
Artifact
SHA256 0B6…7F7
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

2 detail rows

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

42
Noisy-finding weight
x1.00
Publisher domain
vihatsoftware.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
3
Portfolio

13 evidence rows available.

Finding Categories

2
Network

Requested Permissions

4 permissions
<all_urls>

Access and modify data on every website you visit

Dangerous
activeTab
Medium
storage
Low
scripting
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

OMICall is a VoIP call extension with 672 users and developer attribution to [email protected]. The evidence bundle contains exactly 2 findings, both network-type detections with medium severity.

The first finding, titled "NET-FETCH-thirdparty/pancake.js-1", triggers on thirdparty/pancake.js:1. The second finding, titled "NET-FETCH-thirdparty/hubspot.js-1", triggers on thirdparty/hubspot.js:1. Both findings report generic "Network call of type 'fetch' detected" without identifying specific domains or suspicious endpoints.

These files are located in a "thirdparty" directory, which is standard practice for bundling external SDKs and dependencies. HubSpot is a well-known CRM and marketing automation platform with legitimate JavaScript SDKs used for analytics and lead tracking. Pancake is a recognized analytics and conversion tracking service. The presence of fetch calls in these files is expected behavior for analytics SDKs that transmit user interaction data to their respective services.

Critically, the findings summary shows zero malware signatures, zero obfuscation findings, zero IoC findings, and zero code-smell findings. There are no suspicious domains extracted from the code, no credential access patterns, no browser hijacking indicators, and no typosquatting evidence. The extension name "OMICall" does not mimic any popular extension, and the description "Add VoIP call features to any websites" is consistent with legitimate functionality.

The strongest counterargument would be that network fetch calls in any extension could theoretically exfiltrate user data to unknown destinations. However, this argument fails because: (1) the files are explicitly named after known legitimate services (HubSpot, Pancake), not obfuscated or suspicious names; (2) the findings do not reveal any specific suspicious domains—only that fetch calls exist; (3) there is zero obfuscation to hide malicious payloads; (4) there are zero malware signatures; and (5) the developer email indicates a legitimate software company rather than an anonymous publisher. If these were malicious exfiltration channels, we would expect to see obfuscation, suspicious domain IoCs, or malware signatures alongside the network calls.

This extension exhibits the classic pattern of bundled third-party dependencies triggering network findings. The finding count is low (2), the nature of findings is benign (fetch calls in known SDKs), and there is no corroborating evidence of malicious intent. The verdict is likely_false_positive with a recommended action of suppress_false_positive.

Key Reasons

  • Findings limited to fetch calls in thirdparty/ directory
  • Files named after legitimate services (HubSpot, Pancake)
  • Zero malware signatures and zero obfuscation findings
  • No suspicious domains in IoC extraction
  • Developer attribution present with legitimate email domain

False Positive Considerations

  • Third-party SDK files in thirdparty/ directory
  • Legitimate service SDKs (HubSpot, Pancake)
  • Generic fetch call detection without domain specificity
  • Bundled dependency pattern

Reviewed 2026-04-28; recommended action: suppress false positive; model confidence 88%.

Chrome version history

Risk trend by version

3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
44
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
2.0.37
Mar 9, 2026
Risk range
44 to 44
Across analyzed versions
Latest analyzed version
2.0.39
May 31, 2026
Selected version
medium
Version
v2.0.39
4 months ago
Risk score
44
Findings
2
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Bring all VoIP call features from OMICall to any website you want # 2.0.39 (2026-05-27) - Hotfix wrong CDN path for default tenant logo - Update dependency to `[email protected]` # 2.0.38 (2026-03-18) - Hotfix missing Click-to-Call in current contact table list of `hubspot` # 2.0.37 (2026-01-13) - Fix issues for dynamic `WSS URI` of different nation - Update dependency to `[email protected]` Introduction: https://api.omicall.com/sdk/web-extension Changelog : https://api.omicall.com/sdk/web-extension/changelog SDK Changelog: https://api.omicall.com/sdk/web-sdk/v3-changelog

Frequently Asked Questions