Microsoft Edge Add-ons Verified

PrintFriendly: Print, PDF Editor & Full Page Screenshot

a0c836ce-6d2f-5af9-95ae-4ae6bcb088f6 | v7.2.11
85/ 100
CRITICAL risk
No change since v7.2.9
Risk verdict
Do not install

Score-based assessment (critical risk, 85/100). Last analyst review covers version 6.11.10.

Analysis record

Analysed
Yesterday
Version
v7.2.11
Artifact
SHA256 17D…FFB
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

1000 detail rows
Showing 25 of 181 · highest severity first

YARA Rule Matches

21 rules
SeverityRuleHitsFilesMetadata
HIGHMirage APT 1
printfriendly.js
FP 50%
LOWpostinstall persistence mechanism 27
webviewer/lib/core/pdf/PDFworker.js559.js_locales/ca/messages.json +24 more
-
LOWcredential env files 6
webviewer/lib/core/pdf/lean/optimized/PDFNetThreadedWasm.worker.jswebviewer/lib/core/pdf/simple_wasm/MemGrow.jswebviewer/lib/core/pdf/simple_wasm/MemGrow.worker.js +3 more
-
LOWLocalStorageShouldNotBeUsed 5
viewer.jswebviewer/lib/ui/chunks/LPX2DVJX.jstouchpoint-gdocs.js +2 more
-
LOWcredential metamask extension 5
printfriendly.jsoptions.jsbackground.js +2 more
-
LOWUsingCommandLineArguments 1
webviewer/lib/core/pdf/lean/optimized/PDFNetCWasm.js
-
LOWspyeye 2
webviewer/lib/core/pdf/lean/optimized/PDFNetThreadedWasm.br.wasmwebviewer/lib/core/pdf/lean/optimized/PDFNetCWasm.br.wasm
-
LOWDebuggerStatementsShouldNotBeUsed 4
printfriendly.jsbackground.jswebviewer/lib/core/webviewer-core.min.js +1 more
-
LOWpostinstall file download 129
fonts/icomoon/style.css559.jsbackground.js +126 more
-
LOWUntrustedContentShouldNotBeIncluded 1
webviewer/lib/core/webviewer-core.min.js
-
LOWNoUseWeakRandom 27
webviewer/lib/core/external/webcomponents-bundle.jsviewer.jswebviewer/lib/core/pdf/lean/optimized/PDFNetThreadedWasm.br.js.mem +24 more
-
LOWNoUseEval 2
webviewer/lib/core/pdf/WasmThread.jswebviewer/lib/core/webviewer-core.min.js
-
LOWSQLInjection 10
webviewer/lib/core/webviewer-core.min.jswebviewer/lib/ui/chunks/V76R5I3S.jswebviewer/lib/ui/chunks/OHVTHVDR.js +7 more
-
LOWpostinstall obfuscation 76
webviewer/lib/ui/chunks/TBWCL6N7.js_locales/sl/messages.jsonwebviewer/lib/ui/chunks/GDZZJLSC.js +73 more
-
LOWpostinstall system command 90
searchWidget.jssearchWidgetPage.jswebviewer/lib/ui/chunks/ZRZ7XMDJ.js +87 more
-
LOWpostinstall crypto operations 40
webviewer/lib/ui/chunks/3XWQOA7U.jswebviewer/lib/core/pdf/PDFworker.jspdfWrapper.js +37 more
-
LOWpostinstall network communication 132
_locales/en/messages.json_locales/fil/messages.json_locales/uk/messages.json +129 more
-
LOWpostinstall file manipulation 209
webviewer/lib/core/webviewer-core.min.jswebviewer/lib/core/pdf/lean/optimized/PDFNetThreadedWasm.br.js.memwebviewer/lib/ui/chunks/RBW33ACO.js +206 more
-
LOWpostinstall registry modification 14
webviewer/lib/ui/chunks/DBT3UXVS.jswebviewer/lib/ui/chunks/TBWCL6N7.jswebviewer/lib/core/external/webcomponents-bundle.js +11 more
-
LOWpostinstall environment access 33
webviewer/lib/ui/chunks/I37SDUQI.jswebviewer/lib/ui/chunks/7PIIMD67.jswebviewer/lib/ui/chunks/FXUKHJFZ.js +30 more
-
LOWOriginsNotVerified 5
webviewer/lib/core/webviewer-core.min.jswebviewer/lib/ui/chunks/TBWCL6N7.jssearchWidgetPage.js +2 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

1,451 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

Print Friendly LLC

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

38
Noisy-finding weight
x1.00
Publisher domain
printfriendly.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
4
Portfolio

13 evidence rows available.

Finding Categories

1
Malware Signatures
15
Obfuscation
5
Network
1,451
IoC Indicators

YARA Rules Matched

21 rules(819 hits)
Mirage APT postinstall persistence mechanism credential env files LocalStorageShouldNotBeUsed credential metamask extension UsingCommandLineArguments spyeye DebuggerStatementsShouldNotBeUsed postinstall file download UntrustedContentShouldNotBeIncluded NoUseWeakRandom NoUseEval SQLInjection postinstall obfuscation postinstall system command postinstall crypto operations +5 more

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

The PrintFriendly extension (version 6.11.10) presents as a legitimate utility tool published by 'PrintFriendly and PDF', a well-established brand in the PDF/printing space. The extension's stated functionality—printing clean web pages, saving as PDF, taking screenshots, and reader mode—aligns with the known legitimate PrintFriendly service.

Critically, the findings_by_category object is completely empty, meaning zero security findings were detected across all analysis categories including malware signatures, code-smell patterns, IoC extraction, and obfuscation detection. This is a positive signal when combined with the verified publisher identity. The extension name matches the legitimate PrintFriendly brand exactly, with no typosquatting indicators such as character substitution or misleading naming.

The developer attribution is present and matches the expected publisher ('PrintFriendly and PDF'), which eliminates the high-confidence impersonation risk. Extensions from known publishers with accurate attribution receive benefit of the doubt under the CVEQ threat model.

The user count of 0 is anomalous for a well-known extension like PrintFriendly, which typically has substantial user bases. This could indicate: (1) a newly listed version, (2) Edge store data collection lag, or (3) a different listing than the primary Chrome Web Store version. However, user count alone does not indicate malicious behavior and is not a high-confidence threat indicator in the CVEQ framework.

Strongest Counterargument: A skeptic might argue that the empty findings object (findings_by_category: {}) indicates the security scan failed to run or returned incomplete data, warranting an 'incomplete_data' verdict. However, the presence of version metadata (6.11.10), developer name, store information, and extension name indicates the scan did complete and simply found no security issues. The CVEQ framework explicitly states that high finding counts are often false positives from bundled dependencies, while zero findings from a known publisher is a legitimate clean result. If the scan had failed, we would expect missing metadata or version 'unknown', neither of which is present.

The extension's capabilities (page manipulation, PDF generation, screenshot capture) could theoretically be misused for data exfiltration if the extension were compromised, but there is no evidence of such behavior. This justifies the 'benign_but_powerful' classification rather than a simple 'safe' designation.

No action is required. The extension represents a legitimate utility from a verified publisher with no detected security issues.

Key Reasons

  • Verified publisher identity (PrintFriendly and PDF) matches legitimate brand
  • Empty findings_by_category indicates no security issues detected
  • Extension name and description match known legitimate PrintFriendly service
  • No typosquatting or impersonation indicators present
  • User count of 0 is anomalous but not a threat indicator

Reviewed 2026-04-21; recommended action: no action; model confidence 70%.

Edge version history

Risk trend by version

13 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
85
Change since first
+20
Change from previous
No change
Versions:
First analyzed version
6.11.10
Apr 19, 2026
Risk range
65 to 85
Across analyzed versions
Latest analyzed version
7.2.11
Sep 30, 2026
Selected version
critical
Version
v7.2.11
Yesterday
Risk score
85
Findings
2759
Change vs previous
0

Pick any point on the chart to explore that version's code below.

Frequently Asked Questions