Chrome Web Store Verified

Activity Map v4

by [email protected] · 4.0K users · 2.3 rating
5a48ce4b-477c-56d1-aec8-f03127cfbf98 | v4.0.0.57
36/ 100
LOW risk
No change since v4.0.0.56
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
2 days ago
Version
v4.0.0.57
Artifact
SHA256 F3B…F40
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

1 detail row

Publisher Evidence

Low

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

73
Noisy-finding weight
x1.00
Publisher domain
adobe.com
Trusted match
Store verification signal
Limited signal
Limited
Extension portfolio
25
Portfolio

12 evidence rows available.

Finding Categories

Requested Permissions

6 permissions
identity

Access your identity and sign-in tokens

High
activeTab
Medium
tabs
Medium
scripting
Low
storage
Low
https://*/
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

This extension is published by Adobe using the verified email [email protected], which is a strong indicator of legitimacy. The extension's stated purpose is to "view key site metrics in an intuitive visual format," and the code behavior aligns with this functionality.

The analysis detected 14 network-related findings, but these are benign detections of network call types (XMLHttpRequest, socket_io, fetch) rather than suspicious domains. For example, toolbar-body.js contains socket_io calls at lines 55058, 55102, and 58813, which are standard WebSocket communication patterns for real-time data updates. The file sitecatalyst-minify.js at line 30 contains an XMLHttpRequest, and SiteCatalyst is Adobe's legacy analytics platform—this is expected behavior for an Adobe extension, not a security concern.

The manifest.json declares the 'tabs' permission, which triggered a medium-severity manifest analysis finding. This permission is necessary for the extension's core functionality: to display site metrics, the extension must read tab information. This is a legitimate use case, not a privacy violation.

Critically, the analysis found zero malware signatures, zero obfuscation indicators, and zero suspicious network domains. The file ext-base-mbox38-proto1.7.0.0.js at line 6 contains a fetch call, which is standard JavaScript for HTTP requests. The reports-body.js file contains XMLHttpRequest calls at lines 27002 and 26867 for data retrieval, consistent with metrics reporting functionality.

Addressing the strongest counterargument: A skeptic might argue that 14 network findings indicate aggressive data collection or exfiltration. However, the nature of these findings matters more than the count. Each network finding simply detects the presence of a network call type—it does not indicate a suspicious destination. The extension communicates with Adobe's own services (SiteCatalyst) for analytics functionality, which is its documented purpose. There are no external third-party domains, no credential access patterns, and no data exfiltration signatures. The network activity is proportional to the extension's stated goal of displaying site metrics.

The extension has 4,000 users and version 3.0.0.20, indicating ongoing maintenance. Adobe is a well-established software company with no history of malicious browser extensions. The combination of verified publisher identity, functionality matching description, absence of malware signatures, and benign network patterns makes this a clear false positive driven by automated detection of legitimate network calls.

This extension should be suppressed from security alerts as it represents expected behavior for a legitimate analytics tool from a known publisher.

Key Reasons

  • Verified Adobe publisher ([email protected])
  • Zero malware signatures detected
  • Zero obfuscation indicators
  • Network findings are benign call-type detections, not suspicious domains
  • Extension behavior matches documented purpose

False Positive Considerations

  • Network call type detection (not domain-based)
  • Legitimate Adobe analytics services (SiteCatalyst)
  • Tabs permission required for core functionality
  • Known publisher with verified email

Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 88%.

Chrome version history

Risk trend by version

12 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
36
Change since first
-36
Change from previous
No change
Versions:
First analyzed version
3.0.0.20
Apr 11, 2026
Risk range
36 to 74
Across analyzed versions
Latest analyzed version
4.0.0.57
Sep 29, 2026
Selected version
low
Version
v4.0.0.57
2 days ago
Risk score
36
Findings
1
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Adobe Analytics Activity Map See where visitors are interacting with your website! Increase engagement and conversion rates by optimizing your website content, in a visual and intuitive way. Understand where visitors are interacting with your website, where those visitors come from and where they are going. Real-time page analytics Do you need to make real-time decision on your content? Are you obsessed with improving your website design? Activity Map now offers minute granularity to understand link trends. Customer segmentation Do you market to different audiences? What is distracting visitors who reach the shopping cart but do not purchase? With Activity Map, you can create a multi-segment filter Full set of metrics Which links are involved in conversions? How much time are visitors spending on a specific link? Activity Map lets you use all your custom Adobe Analytics metrics

Frequently Asked Questions