Chrome Web Store

AI Sider: ChatGPT + DeepSeek + Gemini

by [email protected] · 20.0K users · 4.9 rating
6a8f808d-7d1e-5293-ac8f-a5598eaf9056 | v6.0.4
61/ 100
MEDIUM risk
No change since v5.2.1
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (61/100) still counts them.

Analysis record

Analysed
1 months ago
Version
v6.0.4
Artifact
SHA256 F2E…968
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

11 detail rows

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

40
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Limited signal
Limited
Extension portfolio
8
Portfolio

12 evidence rows available.

Finding Categories

2
Obfuscation
8
Network

Requested Permissions

20 permissions
<all_urls>

Access and modify data on every website you visit

Dangerous
http://*/*
Dangerous
https://*/*
Dangerous
activeTab
Medium
tabs
Medium
sidePanel
Low
scripting
Low
declarativeNetRequest
Low
clipboardWrite
Low
storage
Low
https://chatgpt.com/*
Low
https://gemini.google.com/*
Low
https://chat.deepseek.com/*
Low
https://www.qianwen.com/*
Low
https://www.doubao.com/*
Low
https://yuanbao.tencent.com/*
Low
https://grok.com/*
Low
https://kimi.moonshot.cn/*
Low
https://*.kimi.com/*
Low
https://*.kimi.ai/*
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

AI Sider: ChatGPT + DeepSeek + Gemini is a browser extension that provides access to multiple AI assistants through a sidebar interface. The security findings for this extension are overwhelmingly driven by known false positive patterns rather than actual malicious behavior.

The extension contains zero malware signatures, which is the most critical indicator of actual malicious code. All 539 IoC findings are from legitimate domains or extraction artifacts. For example, va.truepic.com and c2pa.hash.data are C2PA (Coalition for Content Provenance and Authenticity) domains used for content authenticity verification. The finding xmlhttprequest.prototype.open is a JavaScript property access chain being misread as a domain, a well-documented false positive pattern. Other IoCs include google.com, tailwindcss.com, and cv.iptc.org — all legitimate infrastructure or service domains.

The six network findings originate from content-scripts/smartAnalyzer.js and content-scripts/content.js, which make fetch calls. This is expected behavior for an AI assistant extension that needs to communicate with AI APIs to function. The single manifest finding flags the tabs permission, which is sensitive but necessary for a browser sidebar extension that interacts with web pages.

Sixty code-smell findings are classified as low severity and match basic JavaScript patterns like fetch, crypto, and process.env. These are documented as noise in security analysis and should not drive verdicts.

The strongest counterargument is the anonymous publisher ([email protected]) and high total finding count of 608. However, finding volume is not evidence of malicious intent — the nature of findings matters. The high count is driven by IoC extractor garbage and code-smell noise, not actual threats. The extension's purpose (AI assistant sidebar) is legitimate, and no high-confidence threat indicators like typosquatting, browser hijacking, or credential theft are present. With zero malware signatures and no suspicious domains in the IoC list, this extension represents a classic false positive case where automated scoring inflates risk based on quantity rather than quality of findings.

Key Reasons

  • Zero malware signatures detected
  • IoC findings are from legitimate domains (C2PA, Google, TailwindCSS) or known FP patterns (property access chains)
  • Network calls from content scripts are expected for AI assistant functionality
  • Code-smell findings are documented as noise and should not drive verdicts
  • No high-confidence threat indicators present (no typosquatting, hijacking, or credential theft)

False Positive Considerations

  • IoC extractor garbage (C2PA domains, property access chains misread as domains)
  • Code-smell rules matching basic JavaScript patterns
  • Legitimate infrastructure domains (google.com, tailwindcss.com)
  • Bundled dependency false positives in content scripts

Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 85%.

Chrome version history

Risk trend by version

4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
61
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
5.1.4
Apr 7, 2026
Risk range
61 to 61
Across analyzed versions
Latest analyzed version
6.0.4
Aug 20, 2026
Selected version
medium
Version
v6.0.4
1 months ago
Risk score
61
Findings
11
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

🚀 AI Sider — Your All-in-One AI Sidebar for Chrome 📸 Smart Screenshot & Paste to AI • Full Page Screenshot — Capture the entire visible viewport and send it directly to any AI chatbot. • Region Screenshot — Select a specific area to capture and paste into your AI chat. 📋 Copy & Send Page Context Extract text content from any webpage and send it to your preferred AI for summarization, translation, analysis, or Q&A — all without copy-pasting manually. 📄 DOM File for Deep Analysis Generate a simplified, clean HTML representation of any webpage and upload it as a file to AI chatbots. Perfect for asking AI to analyze page structure, extract data, or debug web issues. 🎬 YouTube Video Summarization Automatically extract YouTube subtitles (with timestamps) and send them to AI for instant video summarization. Never watch a long video just to find the key takeaways. ⚡ Smart Page Actions Context-aware action buttons that adapt to the website you're visiting. Get relevant AI-powered shortcuts based on the page content — configured remotely and always up to date. 🌐 Works on Any Website AI Sider lives in your browser's native side panel. Browse any website while chatting with AI — no popups, no tab-switching, no distractions. 🔒 Privacy & Security • No data collection — your conversations stay between you and the AI providers. • No account required — just install and start using. • Open communication via official AI provider websites only. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 💡 USE CASES • 📝 Summarize articles, PDFs, and web pages • 🌍 Translate content on-the-fly • 💻 Debug code with screenshot context • 🎓 Research and study with AI assistance • 🎬 Get YouTube video summaries in seconds • 📊 Analyze webpage data and structure • ✍️ Draft emails and content while browsing ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 📬 SUPPORT & FEEDBACK Have questions or feature requests? Leave a review or reach out — we're constantly improving AI Sider based on your feedback!

Frequently Asked Questions