Is "Sourcegraph for Firefox" on Firefox Add-ons Safe to Install?

Sourcegraph · firefox · v23.4.14.1343

The open-source Sourcegraph extension adds code navigation and code intelligence to GitHub, GitHub Enterprise, GitLab, Bitbucket Server, and Phabricator. • Code intelligence on your code host: * Hover tooltips with documentation and type information * Go to definition * Find references • Integrations with third-party services like Codecov coverage overlays, open-in-editor buttons and many more with Sourcegraph extensions • Browser shortcut (src + Space) that performs the search on your Sourcegraph instance It works for 20+ languages on public and private code on popular code hosts (see below). Make it work on your code host: • GitHub - No action required. Your extension works here by default. • GitHub Enterprise, GitLab, Bitbucket Server and Phabricator - grant additional permissions in the extension menu Browser extension docs: https://docs.sourcegraph.com/integration/browser_extension Make it work for private code: To use the browser extension with your private repositories, you need to set up a private Sourcegraph instance and connect it to the extension. Installation docs: https://docs.sourcegraph.com/admin/install Where to start? After adding the extension you install it, try it out on any of these public repositories: • Go: https://github.com/gorilla/mux/blob/9e1f59/mux.go or https://github.com/dgrijalva/jwt-go/pull/152/files#diff-f615844d3497ff38db57e459d6ef657bL48 • Java: https://github.com/google/guava/blob/581ba1/guava/src/com/google/common/collect/ImmutableList.java • TypeScript: https://github.com/angular/angular/blob/a2878b/packages/benchpress/src/reporter/console_reporter.ts or https://github.com/sindresorhus/got/pull/917/files#diff-02301bc46e8b878f10e9a8339efb7de7R176 • C#: https://github.com/paiden/Nett/pull/76/files#diff-e969e1315b2cb01bab80b2860be0d87eR52 • Python: https://github.com/ageitgey/face_recognition/blob/b8fed6/examples/facerec_on_raspberry_pi.py This extension is open source: https://github.com/sourcegraph/sourcegraph/tree/master/browser

Risk Assessment

Pending
0
out of 100
MINIMAL

0 security findings detected across all analyzers

Firefox extension requesting 9 permissions

No Threats Detected

This extension passed all security checks

About This Extension

The open-source Sourcegraph extension adds code navigation and code intelligence to GitHub, GitHub Enterprise, GitLab, Bitbucket Server, and Phabricator. • Code intelligence on your code host: * Hover tooltips with documentation and type information * Go to definition * Find references • Integrations with third-party services like Codecov coverage overlays, open-in-editor buttons and many more with Sourcegraph extensions • Browser shortcut (src + Space) that performs the search on your Sourcegraph instance It works for 20+ languages on public and private code on popular code hosts (see below). <strong>Make it work on your code host:</strong> • GitHub - No action required. Your extension works here by default. • GitHub Enterprise, GitLab, Bitbucket Server and Phabricator - grant additional permissions in the extension menu Browser extension docs: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/e8c426ee279e08f2ac84eceafb293817b2dfa7df0ec26fdd9598c2a1a5505d21/https%3A//docs.sourcegraph.com/integration/browser_extension" rel="nofollow">https://docs.sourcegraph.com/integration/browser_extension</a> <strong>Make it work for private code:</strong> To use the browser extension with your private repositories, you need to set up a private Sourcegraph instance and connect it to the extension. Installation docs: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/ee1ff40714c6b3f844fdcd86938b5f63abacd0d6569004627be056cbc22f4f45/https%3A//docs.sourcegraph.com/admin/install" rel="nofollow">https://docs.sourcegraph.com/admin/install</a> <strong>Where to start?</strong> After adding the extension you install it, try it out on any of these public repositories: • Go: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/fea14027259b058fa9c05268eb4d8a78d04357700edb62f1c62805c2c5163701/https%3A//github.com/gorilla/mux/blob/9e1f59/mux.go" rel="nofollow">https://github.com/gorilla/mux/blob/9e1f59/mux.go</a> or <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/848ec07df78de6f3c080086827d67ffc0c4d94b6d3f14131abae0f2699ceef94/https%3A//github.com/dgrijalva/jwt-go/pull/152/files%23diff-f615844d3497ff38db57e459d6ef657bL48" rel="nofollow">https://github.com/dgrijalva/jwt-go/pull/152/files#diff-f615844d3497ff38db57e459d6ef657bL48</a> • Java: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/a07300d4cc8c85b825913ed89a09897f2242b76a42917bf327a820dabc38c67f/https%3A//github.com/google/guava/blob/581ba1/guava/src/com/google/common/collect/ImmutableList.java" rel="nofollow">https://github.com/google/guava/blob/581ba1/guava/src/com/google/common/collect/ImmutableList.java</a> • TypeScript: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/02689d907172b86d44d5173e38cae551b771e874ef67bf0472c84b0bb3abd612/https%3A//github.com/angular/angular/blob/a2878b/packages/benchpress/src/reporter/console_reporter.ts" rel="nofollow">https://github.com/angular/angular/blob/a2878b/packages/benchpress/src/reporter/console_reporter.ts</a> or <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/f1c4a5e821d1c03f5bf5c41df02aaa8c76a9a7ccf4f6b124f11acc09a28809db/https%3A//github.com/sindresorhus/got/pull/917/files%23diff-02301bc46e8b878f10e9a8339efb7de7R176" rel="nofollow">https://github.com/sindresorhus/got/pull/917/files#diff-02301bc46e8b878f10e9a8339efb7de7R176</a> • C#: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/8e5bce1d49862dada012e41fdca8060f3348274da597ae9c9039faa2a7d7908f/https%3A//github.com/paiden/Nett/pull/76/files%23diff-e969e1315b2cb01bab80b2860be0d87eR52" rel="nofollow">https://github.com/paiden/Nett/pull/76/files#diff-e969e1315b2cb01bab80b2860be0d87eR52</a> • Python: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/d924dc217f7b4eea72488c3eeaa90b2fd2813d43fcf60301b2644cf5f4224cce/https%3A//github.com/ageitgey/face_recognition/blob/b8fed6/examples/facerec_on_raspberry_pi.py" rel="nofollow">https://github.com/ageitgey/face_recognition/blob/b8fed6/examples/facerec_on_raspberry_pi.py</a> This extension is open source: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/b03e0b24231ff2b968d8beb3aa6305d85ca982d60e47617cba30db04da02a4dc/https%3A//github.com/sourcegraph/sourcegraph/tree/master/browser" rel="nofollow">https://github.com/sourcegraph/sourcegraph/tree/master/browser</a>

No Findings

All security checks passed

Security Analysis Summary

Security Analysis Overview

Sourcegraph for Firefox is a Firefox Add-ons extension published by Sourcegraph. Version 23.4.14.1343 has been analyzed by the Risky Plugins security platform, receiving a risk score of 0/100 (MINIMAL risk) based on 0 security findings.

Risk Assessment

This extension presents minimal security concerns. The automated analysis found very few or no issues, suggesting it is suitable for general use.

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

Sourcegraph for Firefox is published by Sourcegraph on the Firefox Add-ons marketplace. The extension has approximately 516 users.

Recommendation

Based on the automated security analysis, this extension appears safe for general use. As with any extension, users should review the requested permissions before installation.

Frequently Asked Questions