Microsoft Edge Add-ons Verified

Smarty

ace521da-b918-5679-b663-d8258cb37164 | v8.9.15
65/ 100
MEDIUM risk
No change since v8.9.14
Risk verdict
Review before use

Score-based assessment (medium risk, 65/100). No analyst review available.

Analysis record

Analysed
6 days ago
Version
v8.9.15
Artifact
SHA256 599…E6E
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

451 detail rows
Showing 25 of 237 · highest severity first

YARA Rule Matches

15 rules
SeverityRuleHitsFilesMetadata
LOWcredential env files 5
js/background.jsjs/content_script.jsjs/libs/vue.runtime.min.js +2 more
-
LOWpostinstall persistence mechanism 5
js/content_script.jsjs/libs/bootstrap.bundle.jsjs/background.js +2 more
-
LOWCreatingCookiesWithoutTheHttpOnlyFlag 3
js/popups/popup.jsjs/content_script.jsjs/background.js
-
LOWNoDisableSanitizeHtml 1
js/libs/mustache.min.js
-
LOWpostinstall file download 27
js/metadata/womanwithin/womanwithin.jsjs/metadata/dellhomeandoffice/dell.jsjs/metadata/blair/blair.js +24 more
-
LOWNoUseWeakRandom 11
js/libs/jquery-3.4.1.min.jsjs/background.jsjs/metadata/newegg/newegg.js +8 more
-
LOWSQLInjection 2
js/libs/bootstrap.bundle.jsjs/libs/jquery-3.4.1.min.js
-
LOWLocalStorageShouldNotBeUsed 1
js/background.js
-
LOWpostinstall crypto operations 10
js/libs/aes-json-format.jsjs/background.jsjs/libs/jquery-3.4.1.min.js +7 more
-
LOWpostinstall network communication 44
js/page_utils.jsjs/metadata/sears/sears.jsjs/popups/popup.js +41 more
-
LOWpostinstall file manipulation 68
js/metadata/predefined/salesforce.jsjs/metadata/predefined/magento2.jsjs/metadata/predefined/dom.js +65 more
-
LOWpostinstall system command 17
js/background.jsjs/metadata/blair/blair.jsjs/popups/popup.js +14 more
-
LOWpostinstall environment access 7
js/metadata/predefined/oracle.jsjs/metadata/predefined/salesforce.jsjs/metadata/kohls/kohls.js +4 more
-
LOWpostinstall obfuscation 12
js/libs/bootstrap.bundle.js.mapjs/libs/aes-json-format.jsjs/background.js +9 more
-
LOWOriginsNotVerified 1
js/content_script.js
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

522 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

JoinSmarty, LLC

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

42
Noisy-finding weight
x1.00
Publisher domain
joinsmarty.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
4
Portfolio

12 evidence rows available.

Finding Categories

5
Obfuscation
92
Network
522
IoC Indicators

YARA Rules Matched

15 rules(214 hits)
credential env files postinstall persistence mechanism CreatingCookiesWithoutTheHttpOnlyFlag NoDisableSanitizeHtml postinstall file download NoUseWeakRandom SQLInjection LocalStorageShouldNotBeUsed postinstall crypto operations postinstall network communication postinstall file manipulation postinstall system command postinstall environment access postinstall obfuscation OriginsNotVerified

Security Analysis Summary

Security Analysis Overview

Smarty is a Microsoft Edge Add-ons extension published by JoinSmarty, LLC. Version 8.9.15 has been analyzed by the Risky Plugins security platform, receiving a risk score of 64.99/100 (MEDIUM risk) based on 973 security findings.

Risk Assessment

This extension presents moderate security risk. Several findings were detected that may warrant attention. Users should carefully review the permissions and findings before installation.

Findings Breakdown

  • High: 1 finding(s)
  • Medium: 618 finding(s)
  • Low: 214 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

Smarty is published by JoinSmarty, LLC on the Microsoft Edge Add-ons marketplace.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

Edge version history

Risk trend by version

4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
65
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
8.9.12.1
Jul 11, 2026
Risk range
65 to 65
Across analyzed versions
Latest analyzed version
8.9.15
Sep 25, 2026
Selected version
medium
Version
v8.9.15
6 days ago
Risk score
65
Findings
973
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

Frequently Asked Questions