Chrome Web Store

Quiz Boost AI - Smart Test Assistant, Exam Helper & Homework Quiz Solver

by [email protected] · 107 users · 5.0 rating
5c4cda54-2d26-52b2-b14f-d4ef5ee374af | v1.0.3
56/ 100
MEDIUM risk
No change since v1.0.2
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (56/100) still counts them.

Analysis record

Analysed
6 months ago
Version
v1.0.3
Artifact
SHA256 5ED…97C
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

41 detail rows

YARA Rule Matches

9 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall crypto operations 2
assets/client-BrKYtKys.js_metadata/verified_contents.json
-
LOWpostinstall system command 8
assets/FloatButton.tsx-loader-8zI3xk8h.jsassets/index.html-CXa_mNQz.jsassets/inject.ts-loader-ldqJW7Ge.js +5 more
-
LOWpostinstall file manipulation 6
assets/client-BrKYtKys.jsassets/inject.ts-B9mywqQj.jsassets/FloatButton.tsx-CMq4At7t.js +3 more
-
LOWpostinstall environment access 5
assets/client-BrKYtKys.jsassets/inject.ts-B9mywqQj.jsassets/FloatButton.tsx-CMq4At7t.js +2 more
-
LOWpostinstall obfuscation 3
assets/index.html-CXa_mNQz.jsassets/client-BrKYtKys.jsassets/inject.ts-B9mywqQj.js
-
LOWpostinstall network communication 7
assets/index.html-CXa_mNQz.jsassets/client-BrKYtKys.jsassets/inject.ts-B9mywqQj.js +4 more
-
LOWpostinstall file download 4
assets/index.html-CXa_mNQz.jsassets/client-BrKYtKys.jsassets/inject.ts-B9mywqQj.js +1 more
-
LOWNoUseWeakRandom 2
assets/index.html-CXa_mNQz.jsassets/client-BrKYtKys.js
-
LOWpostinstall persistence mechanism 1
assets/background.ts-BRGTSiMA.js
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

79 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

43
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Limited signal
Limited
Extension portfolio
10
Portfolio

11 evidence rows available.

Finding Categories

3
Network
79
IoC Indicators

YARA Rules Matched

9 rules(38 hits)
postinstall crypto operations postinstall system command postinstall file manipulation postinstall environment access postinstall obfuscation postinstall network communication postinstall file download NoUseWeakRandom postinstall persistence mechanism

Requested Permissions

4 permissions
<all_urls>

Access and modify data on every website you visit

Dangerous
activeTab
Medium
storage
Low
notifications
Low

AI Security Report

AI Security Review

Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-04-28. The review verdict is likely false positive with 85% confidence.

Recommended action: suppress false positive. Evidence context: threat category none; evidence quality weak.

This extension's security findings are entirely consistent with known false-positive patterns in the CVEQ detection system. The 115 IoC findings shown in the evidence bundle are not real network indicators—they are JavaScript property access chains misidentified as domains by the XIOC extractor. For example, findings like XIOC-DOMAIN-e.target, XIOC-DOMAIN-r.data, XIOC-DOMAIN-h.target, and XIOC-DOMAIN-se.prototype.tostring.call are not domains at all; they are standard JavaScript syntax where e.target and r.data represent object property access. The threat model explicitly documents this as "Property access chains misread as domains: b.call, h.next, g.id" and states these are benign.

The network findings are equally benign. The single network finding shown, NET-FETCH-assets/index.html-CXa_mNQz.js-1, indicates a fetch call to a local asset file within the extension's own directory structure (assets/index.html-CXa_mNQz.js). This is standard behavior for any extension loading its own resources and poses no security risk.

Critically, there are zero malware signatures, zero obfuscation findings, and zero critical or high severity findings. The 38 code-smell findings are classified as low severity, which the threat model explicitly states are "NOISE" and should "NEVER drive a verdict." The extension's functionality—a quiz/test assistant—is a legitimate category with no inherent security concerns.

The strongest counterargument to this verdict would be the developer's use of a generic email address ([email protected]) rather than a verified publisher name, combined with the high total finding count of 156. However, finding COUNT is explicitly stated in the threat model as "NOT evidence"—only finding NATURE matters. The developer identity concern is valid but insufficient to override the complete absence of actual malicious indicators. A Gmail address as developer attribution is common for individual developers and does not constitute impersonation or deception. The extension does not mimic any known extension name, does not use suspicious domains, and shows no evidence of credential theft, browser hijacking, or malware delivery.

The verdict of likely_false_positive is appropriate because every finding can be explained by documented false-positive patterns, and there is no evidence of intentional harm or risky behavior.

Key Reasons

  • All 115 IoC findings are property access chains misread as domains (e.target, r.data, h.target, etc.)
  • Zero malware signatures detected
  • Zero obfuscation findings
  • Network findings reference only local asset files
  • Code-smell findings are low severity noise per threat model

False Positive Considerations

  • XIOC property access chain misidentification
  • Code-smell low severity findings
  • High finding count from bundled dependencies

Chrome version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
56
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
1.0.2
Mar 8, 2026
Risk range
56 to 56
Across analyzed versions
Latest analyzed version
1.0.3
Mar 22, 2026
Selected version
medium
Version
v1.0.3
6 months ago
Risk score
56
Findings
120
Change vs previous
0

Pick any point on the chart to explore that version's code below.

About This Extension

⭐ QuizBoost – Your AI Homework & Study Assistant QuizBoost is an AI homework helper designed to make online learning smoother, faster, and more effective. Whether you're working through assignments, reviewing course materials, or trying to better understand complex concepts, QuizBoost gives you instant support—right inside your browser. 🚀 Boost Your Learning - Get Instant answers by accessing Invisible AI assistance directly on learning platforms - Stay focused without switching tabs - Works on multiple question types (multiple choice, multiple select, matching, short answer, fill‑in‑the‑blank, and more) - Integrates seamlessly with popular learning systems such as Canvas, Blackboard, Moodle, D2L Brightspace, Schoology, and many others—making it easier to study and complete assignments efficiently. 🔒 Private, Secure, and Undetectable Your learning activity stays private. QuizBoost only activates when you choose to use it, and all data is encrypted to ensure a safe study experience. ⚙️ How It Works Using QuizBoost is simple: 1. Activate the extension on your learning platform 2. Wait 25 seconds for QuizBoost AI to analyze the page 3. Double‑click any question to auto fill suggested answers This workflow is designed for assignments, practice quizzes, and study sessions, helping you learn more efficiently. ⚠️ Important Note QuizBoost is designed only for studying, learning, and completing homework responsibly. Please do not use QuizBoost during exams, tests, or any proctored exams. Always follow your institution’s academic integrity guidelines. 📌 Disclaimer QuizBoost is an independent tool and is not affiliated with Canvas, Blackboard, Moodle, D2L, Schoology, or any other educational platform. All trademarks belong to their respective owners.

Frequently Asked Questions