Firefox Add-ons Verified

Kindredly - A safer, private web for families

by Kindredly.ai · 5 users
9fc32f05-a3c0-5607-93f1-31e3ac7cf6e0 | v3.1.1.3
86/ 100
CRITICAL risk
No change since v3.1.1.2
Risk verdict
Do not install

Score-based assessment (critical risk, 86/100). No analyst review available.

Analysis record

Analysed
Today
Version
v3.1.1.3
Artifact
SHA256 E27…095
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

1000 detail rows
Showing 25 of 60 · highest severity first

YARA Rule Matches

19 rules
SeverityRuleHitsFilesMetadata
HIGHsupply chain sourcemap appended iife 1
sandbox-nonet.html
-
LOWLocalStorageShouldNotBeUsed 12
content-script-usage-status.jsjs/devProviderAuthDjiXxR_E.jsjs/EbookReaderDluY3NMC.js +9 more
-
LOWDebuggerStatementsShouldNotBeUsed 2
js/AppCreatorPage4Q4EFJLd.jsjs/compiler-sfc.esm-browserCVZUaTm1.js
-
LOWUsingCommandLineArguments 3
modeldata/wasm/ort-wasm-simd-threaded.jsep.mjsjs/heic2anyDpG77T-a.jsjs/baseDeYcB21j.js
-
LOWcredential metamask extension 1
js/thing-extractionByhH0tyb.js
-
LOWpostinstall persistence mechanism 39
js/remoteActionApprovalDje_jgV4.jsjs/esbuildInitDBiK-qb1.jsjs/FamilyDowntimeDDu0sayd.js +36 more
-
LOWcredential env files 23
js/bgrouterBg6h9N57.jsjs/aiBridgeGuestDBM2NMtt.jsjs/Unique_implBPx-Abuh.js +20 more
-
LOWcredential skype data 1
js/deviceAppPolicykAZDt1pd.js
-
LOWpostinstall file download 142
js/MyUserFilesDvoKdJbg.jsjs/AppCreatorPage4Q4EFJLd.jsjs/AIAdvancedSettingsDKv5FsNG.js +139 more
-
LOWNoUseEval 1
js/vue3-lottie.esB7tbifYd.js
-
LOWNoUseWeakRandom 51
js/compiler-sfc.esm-browserCVZUaTm1.jscontent-script-reddit-distractions.jsjs/SearchHomeDIJRYXJS.js +48 more
-
LOWUntrustedContentShouldNotBeIncluded 1
js/EbookReaderDluY3NMC.js
-
LOWUsingIntrusivePermissionsWithGeolocation 2
js/AppIFrameDESxs7JE.jsjs/ItemQPTiw26f.js
-
LOWSQLInjection 4
js/ort.bundle.minCVbVYmDH.jsjs/AppCreatorPage4Q4EFJLd.jsjs/ItemListayqb2Toh.js +1 more
-
LOWpostinstall crypto operations 128
js/AppCreatorPage4Q4EFJLd.jsjs/ForgotPasswordRecoveryCgB_X68k.jsjs/CreatePostBaYk8_gK.js +125 more
-
LOWpostinstall file manipulation 267
js/AccountDetailsDpt2agSn.jsjs/EmailSettingsC2GR6gEW.jsjs/LibraryByUsageTypevYQL8GbR.js +264 more
-
LOWpostinstall environment access 189
js/UsersListD1I4EKnI.jsjs/remoteActionApprovalDje_jgV4.jsjs/dexie2jmnBxhj.js +186 more
-
LOWpostinstall registry modification 2
js/UserClientListZaT2b8w2.jsmodeldata/wasm/ort-wasm-simd-threaded.jsep.wasm
-
LOWpostinstall system command 71
assets/AppPopup.cssjs/CreatePostBaYk8_gK.jsmodeldata/wasm/tfjs-backend-wasm-threaded-simd.wasm +68 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

1,517 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

Kindredly.ai

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

41
Noisy-finding weight
x1.00
Publisher domain
kindredly.ai
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
2
Portfolio

11 evidence rows available.

Finding Categories

1
Malware Signatures
9
Obfuscation
48
Network
1,517
IoC Indicators

YARA Rules Matched

19 rules(940 hits)
supply chain sourcemap appended iife LocalStorageShouldNotBeUsed DebuggerStatementsShouldNotBeUsed UsingCommandLineArguments credential metamask extension postinstall persistence mechanism credential env files credential skype data postinstall file download NoUseEval NoUseWeakRandom UntrustedContentShouldNotBeIncluded UsingIntrusivePermissionsWithGeolocation SQLInjection postinstall crypto operations postinstall file manipulation +3 more

Requested Permissions

12 permissions
<all_urls>

Access and modify data on every website you visit

Dangerous
nativeMessaging

Exchange messages with programs outside the browser

Dangerous
activeTab
Medium
tabs
Medium
bookmarks
Medium
scripting
Low
storage
Low
unlimitedStorage
Low
alarms
Low
webNavigation
Low
contextMenus
Low
trialML
Low

Security Analysis Summary

Security Analysis Overview

Kindredly - A safer, private web for families is a Firefox Add-ons extension published by Kindredly.ai. Version 3.1.1.3 has been analyzed by the Risky Plugins security platform, receiving a risk score of 86.18/100 (CRITICAL risk) based on 3025 security findings.

Risk Assessment

This extension presents critical security risk. Severe issues were detected, potentially including malware indicators, exposed secrets, or dangerous behaviors. Installation is strongly discouraged until these issues are addressed.

Findings Breakdown

  • High: 3 finding(s)
  • Medium: 1575 finding(s)
  • Low: 1447 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

Kindredly - A safer, private web for families is published by Kindredly.ai on the Firefox Add-ons marketplace. The extension has approximately 5 users.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

Firefox version history

Risk trend by version

13 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
86
Change since first
+1
Change from previous
No change
Versions:
First analyzed version
3.0.235
Jun 28, 2026
Risk range
85 to 86
Across analyzed versions
Latest analyzed version
3.1.1.3
Sep 20, 2026
Selected version
critical
Version
v3.1.1.3
Today
Risk score
86
Findings
3025
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Kindredly helps families create a safer, more meaningful web experience together. Build private collections of trusted websites, videos, and resources. Share them with family members through a private, family-only network designed to make it easy to pass along what matters. With family-friendly browsing, content filtering, and usage limits, Kindredly helps reduce distractions, avoid junk, and guide kids toward higher-quality content. Kindredly is built for families who want more than basic blocking. It combines private sharing, guided browsing, and healthier digital habits in one place. Sensitive family content stays private, with end-to-end encryption built into the platform. Features: <ul><li>Build and share private collections with family members</li><li>Family-only sharing through a private internal network</li><li>Library-first browsing for access to trusted content</li><li>Content filtering and usage limits</li><li>Fewer distractions and a more focused web experience</li><li>Free version available with no ads</li></ul> The internet has amazing educational and enriching content, but it is also full of noise, addictive distractions, and inappropriate material. Kindredly helps families get to the good stuff faster and create a better web experience together. By installing, you agree to our terms of use: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/962ecbcd024679a9650e59c1434079043e8a4b093ac0ca1422a264253e12f137/https%3A//kindredly.ai/terms" rel="nofollow">https://kindredly.ai/terms</a>

Frequently Asked Questions