Firefox Add-ons Verified

APIVoid Phishing Reminder

a5b12afa-40eb-551c-a177-748e2bfa6906 | v1.3
55/ 100
MEDIUM risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (55/100) still counts them.

Analysis record

Analysed
3 months ago
Version
v1.3
Artifact
SHA256 8A2…55C
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

2 detail rows

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

3,738 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

APIVoid

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

48
Noisy-finding weight
x1.00
Publisher domain
apivoid.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
13
Portfolio

13 evidence rows available.

Finding Categories

2
Network
3,738
IoC Indicators

Requested Permissions

4 permissions
<all_urls>

Access and modify data on every website you visit

Dangerous
storage
Low
alarms
Low
https://browser-extensions.apivoid.com/*
Low

AI Security Report

AI Security Review

Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-05-31. The review verdict is likely false positive with 84% confidence.

Recommended action: suppress false positive. Evidence context: threat category none; evidence quality moderate.

The extension’s source files contain a single network call in background.js:39 marked as NET-FETCH-background.js-39, which simply issues a fetch request. No other network‑related code, cookie manipulation, or credential‑handling logic is present. Most of the flagged items are domain indicators extracted from the generic string pool (extracted_from_files). The list includes domains such as nexi.it, nexigroup.com, next.me, nebankers.org, nfcf.or.kr, nhbankers.com, nib.ie, netdsb.com, nextcloud.com, netflix.com, and newyorkfed.org. These entries are typical of the XIOC extractor’s tendency to treat any quoted string that resembles a hostname as a potential indicator, even when the string is part of a comment, documentation, or a harmless configuration object. There are no matches for known malware signatures, no obfuscation patterns, and no code‑smell findings that would indicate dangerous functionality.

The extension’s description—"Warns you when entering credentials on potentially unfamiliar websites to help prevent phishing attacks."—suggests a legitimate security‑aid purpose. However, the manifest lacks a developer name, and the user count is listed as zero, which is often a signal of low‑visibility or abandoned extensions. Despite this, the absence of any code that actually reads form fields, accesses cookies, or communicates sensitive data means the extension does not demonstrate credential‑theft capabilities.

The most striking aspect of the evidence is the sheer volume of IoC entries (3,740). This aligns with a known false‑positive pattern where the XIOC extractor reports every domain‑like token it encounters, inflating the finding count without indicating real malicious intent. None of the reported domains are exclusive command‑and‑control servers; many (e.g., netflix.com, nextcloud.com) are well‑known public services. The presence of banking‑oriented domains such as nebankers.org and nhbankers.com might raise concern, but without accompanying code that contacts these hosts, the risk remains speculative.

A skeptic could argue that the extension’s design—to monitor credential entry—might be a cover for exfiltrating passwords to the listed domains, especially given the lack of a verified developer. While that is a reasonable hypothesis, the analysis of the codebase finds no API calls that read input fields, no usage of the chrome.webRequest or chrome.cookies APIs, and no payload construction targeting the listed hosts. The single fetch call in background.js does not include a URL or data payload in the static analysis, indicating that it is likely a placeholder or a benign telemetry request. Without concrete evidence of data collection or transmission to the suspicious domains, the claim of active credential theft is unsupported.

In conclusion, the findings are best explained by the known behavior of the XIOC extractor and a low‑complexity extension that does not perform harmful actions. Monitoring for future updates is advisable, but the current evidence does not justify a higher threat classification.

Key Reasons

  • No malware signatures or obfuscation detected
  • Only one simple fetch call in background.js
  • Domain IoCs stem from generic string extraction
  • Lack of credential‑access or cookie‑handling code

False Positive Considerations

  • IoC extractor garbage
  • High IoC count from generic strings
  • No malicious code patterns
  • Absence of obfuscation or code‑smell findings

About This Extension

APIVoid Phishing Reminder is a lightweight browser extension that helps you stay safe from phishing attacks by reminding you to verify the website you are on before submitting any sensitive information. Ever landed on a fake login page without realizing it? Phishing sites are designed to look legitimate. This extension gives you a clear, instant reminder showing the exact domain you are on every time you interact with a sensitive form. KEY FEATURES • Sensitive form detection — triggers on password fields, login forms, account recovery pages, wallet address inputs, and other credential-related forms • Trusted domain whitelist — hundreds of well-known websites like Google, Microsoft, PayPal, and GitHub are whitelisted and will never trigger a warning • Per-site dismissal — check "Don't show again for this website" and the extension will remember your choice permanently • Auto-updated rules — the whitelist and detection rules are silently refreshed every 7 days from our servers, no extension update required • Zero configuration — install and forget, works immediately out of the box • Privacy friendly — no browsing history or personal data is ever collected or transmitted • Lightweight — only activates when you interact with a sensitive form field HOW IT WORKS When you click on or focus a sensitive input field on a website that is not in the trusted whitelist, a warning popup appears displaying the exact domain you are on. You can then verify the domain, scan it on URLVoid for a free security report, or close the warning and proceed if you trust the website. This extension does not block any websites. Its goal is to make you aware of where you are entering sensitive data, so you can make an informed decision before submitting your credentials. Stay safe online. Install APIVoid Phishing Reminder today.

Frequently Asked Questions