Chrome Web Store Verified

Citrix Web Extension

by [email protected] · 600.0K users · 1.9 rating
74803305-caec-579d-9337-142e99a041ed | v26.1.6
0/ 100
MINIMAL risk
-67 since v26.1.3
67 → 0 · false positives removed
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
5 months ago
Version
v26.1.6
Artifact
SHA256 3BB…990
Source
Findings (non-IoC)

No Findings

All security checks passed

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

57
Noisy-finding weight
x1.00
Publisher domain
cloud.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
8
Portfolio

11 evidence rows available.

No Threats Detected

This extension passed all security checks

AI Security Report

AI Security Review

Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-05-23. The review verdict is likely false positive with 96% confidence.

Recommended action: no action. Evidence context: threat category none; evidence quality strong.

Citrix Web Extension is a browser add‑on that advertises launching Citrix workspaces without an .ica file. The evidence attached to this scorecard contains no malicious indicators. The 'network' category shows zero findings, indicating no external HTTP requests were recorded. The 'obfuscation' category also shows zero findings, meaning no code‑obfuscation techniques were detected. The 'malware-signature' and 'malware' categories are both zero, confirming that no known malware patterns were matched. The 'ioc' category is zero, so no suspicious IP addresses, domains, or URLs were observed. The developer field lists "[email protected]", which aligns with Citrix’s known contact domain and is consistent with an official vendor identity. The extension’s description explicitly states its purpose and does not employ misleading terminology or typosquatting. The 'manifest-analysis' category shows zero findings, indicating that the declared permissions and host permissions are unremarkable and do not include hidden routing or tracking capabilities. No code‑smell findings were recorded, and the dependency category shows zero findings, indicating that bundled libraries do not trigger any known problematic patterns. The 'browser_hijack' category shows zero findings, indicating no alteration of new‑tab pages or default search engines. The 'credential_theft' category shows zero findings, indicating no attempts to read cookies from banking sites such as facebook.com or paypal.com. The 'adware' category shows zero findings, indicating no aggressive advertising behavior. The extension’s user count of 600,000 reflects broad adoption but does not, on its own, imply risk; the lack of any network, obfuscation, or credential‑theft findings demonstrates that the code behaves as described. A skeptic might argue that a high‑profile extension could be repurposed for covert data collection, but the evidence does not support that claim: there are no network calls to unknown domains, no attempts to read cookies from banking sites, no injection of advertising scripts, and no use of VPN or proxy functionality that would route third‑party traffic through users. The only observations are benign UI enhancements described in the public description. Therefore, the extension should be regarded as safe for normal use, and no further monitoring is required unless new evidence emerges.

Key Reasons

  • Zero malicious findings across all categories
  • Developer identified as Citrix
  • Extension name matches legitimate Citrix product
  • No network or credential activity observed

False Positive Considerations

  • No malicious findings
  • Known developer
  • Legitimate description
  • High user count with no risk

About This Extension

Install this extension to detect your locally installed Workspace app from your browser. This will launch your browser with added security and reliability without the need to download an .ica file. Additional benefits to this are screen capture, app protection and seamless service continuity. Once installed, extension has access only to workspace websites (turns green) and don't have access to other websites (grayed out). The browser extension also detects the Workspace app version you are using and displays the version number. This will be accessible for both on-premises and cloud users. Key features ; 1. Reliable: No more failures when launching Citrix workspace virtual desktops and apps, simultaneously launch multiple apps without failure. 2. Secure: No more .ica file download on non-secure devices. 3. App Protection: Prevents screen capture by displaying an IP address watermark. 4. Login timeout tooltip: Prompts users to start using offline mode if the authentication is not successful within 30 seconds. 5. Troubleshooting logs: To help troubleshoot any problems. Note: Feature support depends on the platform support and entitlement

Frequently Asked Questions