Activity Map v4
Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 2 days ago
- Version
- v4.0.0.57
- Artifact
- SHA256 F3B…F40
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
LowPublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
Requested Permissions
6 permissionsAccess your identity and sign-in tokens
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
This extension is published by Adobe using the verified email [email protected], which is a strong indicator of legitimacy. The extension's stated purpose is to "view key site metrics in an intuitive visual format," and the code behavior aligns with this functionality.
The analysis detected 14 network-related findings, but these are benign detections of network call types (XMLHttpRequest, socket_io, fetch) rather than suspicious domains. For example, toolbar-body.js contains socket_io calls at lines 55058, 55102, and 58813, which are standard WebSocket communication patterns for real-time data updates. The file sitecatalyst-minify.js at line 30 contains an XMLHttpRequest, and SiteCatalyst is Adobe's legacy analytics platform—this is expected behavior for an Adobe extension, not a security concern.
The manifest.json declares the 'tabs' permission, which triggered a medium-severity manifest analysis finding. This permission is necessary for the extension's core functionality: to display site metrics, the extension must read tab information. This is a legitimate use case, not a privacy violation.
Critically, the analysis found zero malware signatures, zero obfuscation indicators, and zero suspicious network domains. The file ext-base-mbox38-proto1.7.0.0.js at line 6 contains a fetch call, which is standard JavaScript for HTTP requests. The reports-body.js file contains XMLHttpRequest calls at lines 27002 and 26867 for data retrieval, consistent with metrics reporting functionality.
Addressing the strongest counterargument: A skeptic might argue that 14 network findings indicate aggressive data collection or exfiltration. However, the nature of these findings matters more than the count. Each network finding simply detects the presence of a network call type—it does not indicate a suspicious destination. The extension communicates with Adobe's own services (SiteCatalyst) for analytics functionality, which is its documented purpose. There are no external third-party domains, no credential access patterns, and no data exfiltration signatures. The network activity is proportional to the extension's stated goal of displaying site metrics.
The extension has 4,000 users and version 3.0.0.20, indicating ongoing maintenance. Adobe is a well-established software company with no history of malicious browser extensions. The combination of verified publisher identity, functionality matching description, absence of malware signatures, and benign network patterns makes this a clear false positive driven by automated detection of legitimate network calls.
This extension should be suppressed from security alerts as it represents expected behavior for a legitimate analytics tool from a known publisher.
Key Reasons
- Verified Adobe publisher ([email protected])
- Zero malware signatures detected
- Zero obfuscation indicators
- Network findings are benign call-type detections, not suspicious domains
- Extension behavior matches documented purpose
False Positive Considerations
- Network call type detection (not domain-based)
- Legitimate Adobe analytics services (SiteCatalyst)
- Tabs permission required for core functionality
- Known publisher with verified email
Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 88%.
Chrome version history
Risk trend by version
12 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Adobe Acrobat: PDF edit, convert, sign tools
[email protected]
Adobe Experience Platform Debugger
[email protected]
Adobe Experience Cloud Visual Editing Helper
[email protected]
Adobe Photoshop
[email protected]
Adobe Workfront review tool
[email protected]
AEM Sidekick
[email protected]