PrintFriendly: Print, PDF Editor & Full Page Screenshot
Score-based assessment (critical risk, 85/100). Last analyst review covers version 6.11.10.
Analysis record
- Analysed
- Yesterday
- Version
- v7.2.11
- Artifact
- SHA256 17D…FFB
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
21 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | Mirage APT | 1 | printfriendly.js | FP 50% |
| LOW | postinstall persistence mechanism | 27 | webviewer/lib/core/pdf/PDFworker.js559.js_locales/ca/messages.json +24 more | - |
| LOW | credential env files | 6 | webviewer/lib/core/pdf/lean/optimized/PDFNetThreadedWasm.worker.jswebviewer/lib/core/pdf/simple_wasm/MemGrow.jswebviewer/lib/core/pdf/simple_wasm/MemGrow.worker.js +3 more | - |
| LOW | LocalStorageShouldNotBeUsed | 5 | viewer.jswebviewer/lib/ui/chunks/LPX2DVJX.jstouchpoint-gdocs.js +2 more | - |
| LOW | credential metamask extension | 5 | printfriendly.jsoptions.jsbackground.js +2 more | - |
| LOW | UsingCommandLineArguments | 1 | webviewer/lib/core/pdf/lean/optimized/PDFNetCWasm.js | - |
| LOW | spyeye | 2 | webviewer/lib/core/pdf/lean/optimized/PDFNetThreadedWasm.br.wasmwebviewer/lib/core/pdf/lean/optimized/PDFNetCWasm.br.wasm | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 4 | printfriendly.jsbackground.jswebviewer/lib/core/webviewer-core.min.js +1 more | - |
| LOW | postinstall file download | 129 | fonts/icomoon/style.css559.jsbackground.js +126 more | - |
| LOW | UntrustedContentShouldNotBeIncluded | 1 | webviewer/lib/core/webviewer-core.min.js | - |
| LOW | NoUseWeakRandom | 27 | webviewer/lib/core/external/webcomponents-bundle.jsviewer.jswebviewer/lib/core/pdf/lean/optimized/PDFNetThreadedWasm.br.js.mem +24 more | - |
| LOW | NoUseEval | 2 | webviewer/lib/core/pdf/WasmThread.jswebviewer/lib/core/webviewer-core.min.js | - |
| LOW | SQLInjection | 10 | webviewer/lib/core/webviewer-core.min.jswebviewer/lib/ui/chunks/V76R5I3S.jswebviewer/lib/ui/chunks/OHVTHVDR.js +7 more | - |
| LOW | postinstall obfuscation | 76 | webviewer/lib/ui/chunks/TBWCL6N7.js_locales/sl/messages.jsonwebviewer/lib/ui/chunks/GDZZJLSC.js +73 more | - |
| LOW | postinstall system command | 90 | searchWidget.jssearchWidgetPage.jswebviewer/lib/ui/chunks/ZRZ7XMDJ.js +87 more | - |
| LOW | postinstall crypto operations | 40 | webviewer/lib/ui/chunks/3XWQOA7U.jswebviewer/lib/core/pdf/PDFworker.jspdfWrapper.js +37 more | - |
| LOW | postinstall network communication | 132 | _locales/en/messages.json_locales/fil/messages.json_locales/uk/messages.json +129 more | - |
| LOW | postinstall file manipulation | 209 | webviewer/lib/core/webviewer-core.min.jswebviewer/lib/core/pdf/lean/optimized/PDFNetThreadedWasm.br.js.memwebviewer/lib/ui/chunks/RBW33ACO.js +206 more | - |
| LOW | postinstall registry modification | 14 | webviewer/lib/ui/chunks/DBT3UXVS.jswebviewer/lib/ui/chunks/TBWCL6N7.jswebviewer/lib/core/external/webcomponents-bundle.js +11 more | - |
| LOW | postinstall environment access | 33 | webviewer/lib/ui/chunks/I37SDUQI.jswebviewer/lib/ui/chunks/7PIIMD67.jswebviewer/lib/ui/chunks/FXUKHJFZ.js +30 more | - |
| LOW | OriginsNotVerified | 5 | webviewer/lib/core/webviewer-core.min.jswebviewer/lib/ui/chunks/TBWCL6N7.jssearchWidgetPage.js +2 more | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidencePrint Friendly LLC
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
YARA Rules Matched
21 rules(819 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
The PrintFriendly extension (version 6.11.10) presents as a legitimate utility tool published by 'PrintFriendly and PDF', a well-established brand in the PDF/printing space. The extension's stated functionality—printing clean web pages, saving as PDF, taking screenshots, and reader mode—aligns with the known legitimate PrintFriendly service.
Critically, the findings_by_category object is completely empty, meaning zero security findings were detected across all analysis categories including malware signatures, code-smell patterns, IoC extraction, and obfuscation detection. This is a positive signal when combined with the verified publisher identity. The extension name matches the legitimate PrintFriendly brand exactly, with no typosquatting indicators such as character substitution or misleading naming.
The developer attribution is present and matches the expected publisher ('PrintFriendly and PDF'), which eliminates the high-confidence impersonation risk. Extensions from known publishers with accurate attribution receive benefit of the doubt under the CVEQ threat model.
The user count of 0 is anomalous for a well-known extension like PrintFriendly, which typically has substantial user bases. This could indicate: (1) a newly listed version, (2) Edge store data collection lag, or (3) a different listing than the primary Chrome Web Store version. However, user count alone does not indicate malicious behavior and is not a high-confidence threat indicator in the CVEQ framework.
Strongest Counterargument: A skeptic might argue that the empty findings object (findings_by_category: {}) indicates the security scan failed to run or returned incomplete data, warranting an 'incomplete_data' verdict. However, the presence of version metadata (6.11.10), developer name, store information, and extension name indicates the scan did complete and simply found no security issues. The CVEQ framework explicitly states that high finding counts are often false positives from bundled dependencies, while zero findings from a known publisher is a legitimate clean result. If the scan had failed, we would expect missing metadata or version 'unknown', neither of which is present.
The extension's capabilities (page manipulation, PDF generation, screenshot capture) could theoretically be misused for data exfiltration if the extension were compromised, but there is no evidence of such behavior. This justifies the 'benign_but_powerful' classification rather than a simple 'safe' designation.
No action is required. The extension represents a legitimate utility from a verified publisher with no detected security issues.
Key Reasons
- Verified publisher identity (PrintFriendly and PDF) matches legitimate brand
- Empty findings_by_category indicates no security issues detected
- Extension name and description match known legitimate PrintFriendly service
- No typosquatting or impersonation indicators present
- User count of 0 is anomalous but not a threat indicator
Reviewed 2026-04-21; recommended action: no action; model confidence 70%.
Edge version history
Risk trend by version
13 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace