Firefox Add-ons

Code Verify

by Meta Extensions · 727 users · 3.2 rating
b6768d1b-966a-5dab-adb8-53b954689c77 | v4.2.0
84/ 100
HIGH risk
+20 since v4.1.0
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (84/100) still counts them.

Analysis record

Analysed
2 weeks ago
Version
v4.2.0
Artifact
SHA256 303…DE2
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

14 detail rows

YARA Rule Matches

1 rule
SeverityRuleHitsFilesMetadata
HIGHsupply chain sourcemap appended iife 4
contentFB.jscontentIG.jscontentWA.js +1 more
-

Publisher Evidence

Limited evidence

Meta Extensions

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

24
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Limited signal
Limited
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

4
Malware Signatures
1
Obfuscation
9
Network

YARA Rules Matched

1 rule(4 hits)
supply chain sourcemap appended iife

Requested Permissions

10 permissions
webRequest

Intercept, modify, and block all network requests

High
storage
Low
https://*.privacy-auditability.cloudflare.com/*
Low
https://static.xx.fbcdn.net/
Low
https://static.cdninstagram.com/
Low
https://static.whatsapp.net/
Low
*://*.messenger.com/*
Low
*://*.facebook.com/*
Low
*://*.instagram.com/*
Low
*://*.whatsapp.com/*
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Code Verify (Firefox, v4.1.0) generates 267 total findings, but the evidence reveals these are false positives from known CVEQ noise patterns.

IoC findings are documentation references, not network destinations. All 204 IoC findings point to https://www.ecma-international.org/ecma-262/8.0/ paths such as XIOC-URL-https://www.ecma-international.org/ecma-262/8.0/#prod-annexB-IdentityEscape and XIOC-URL-https://www.ecma-international.org/ecma-262/8.0/#prod-CharacterClassEscape. These are JavaScript language specification documentation links embedded in code comments or strings. The XIOC extractor incorrectly parses these as suspicious URLs. This matches the documented false positive pattern where property access chains and documentation links trigger IoC matches.

Network findings are generic fetch calls without suspicious destinations. The 9 network findings show NET-FETCH-contentWA.js-185, NET-FETCH-contentFB.js-708, NET-FETCH-contentIG.js-708, NET-FETCH-contentMSGR.js-708, and NET-FETCH-background.js-627. These are standard JavaScript fetch() API calls. The file names (contentWA.js, contentFB.js, contentIG.js, contentMSGR.js) indicate content scripts for WhatsApp, Facebook, Instagram, and Messenger platforms. This naming pattern is consistent with a legitimate extension that interacts with social media sites for its stated purpose of code verification. No specific suspicious domains appear in these network findings.

Zero malware signatures eliminate confirmed malicious intent. The findings summary shows "malware-signature":"0" and "malware":"0". This is decisive evidence against malicious behavior. Real malware extensions trigger at least one malware family signature when combined with obfuscation or suspicious domains. This extension has neither.

Code-smell findings are noise. The 52 code-smell findings fire on standard JavaScript patterns. As documented in CVEQ guidelines, rules like postinstall_*, credential_*, and code-quality checks match almost any non-trivial JavaScript and should not drive verdicts.

The strongest counterargument is the empty developer name. A skeptic would argue that "developer_name": "" combined with 267 findings indicates a suspicious, anonymous publisher. However, the nature of the findings matters more than the count. The 204 IoC findings are documentation links, the 52 code-smell findings are noise, and the 9 network findings are generic fetch calls. The 2 obfuscation findings require inspection but without malware signatures or suspicious domains, they do not constitute evidence of malicious intent. Developer attribution is a weak signal compared to concrete behavioral evidence.

Verdict justification. This extension matches the "What is Almost Always Benign" profile: high IoC counts from documentation references, code-smell findings from standard JavaScript, and zero malware signatures. The extension name "Code Verify" and description "verify the code running in your browser matches what was published" align with the content script file names targeting social media platforms. Suppress this false positive.

Key Reasons

  • All 204 IoC findings are ecma-international.org documentation URLs, not actual network destinations
  • Zero malware signatures detected despite 267 total findings
  • Network findings are generic fetch() calls without suspicious domains
  • File naming (contentWA.js, contentFB.js, contentIG.js) matches stated purpose of social media code verification
  • Code-smell findings are documented false positive noise

False Positive Considerations

  • XIOC documentation URL extraction
  • Generic fetch() API detection
  • Code-smell rules on standard JavaScript
  • Empty developer name (weak signal)

Reviewed 2026-04-29; recommended action: suppress false positive; model confidence 85%.

Firefox version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
84
Change since first
+20
Change from previous
+20
Versions:
First analyzed version
4.1.0
Apr 3, 2026
Risk range
63 to 84
Across analyzed versions
Latest analyzed version
4.2.0
Sep 14, 2026
Selected version
high
Version
v4.2.0
2 weeks ago
Risk score
84
Findings
14
Change vs previous
+20

Pick any point on the chart to explore that version's code below.

About This Extension

Overview An extension to verify that the code running in your browser matches what was published. VERIFY AUTHENTICITY OF YOUR CLIENT The new Code Verify is an open-source browser extension that lets you verify the authenticity of the WhatsApp, Facebook, Instagram, or Messenger client that you are being served when you use them on the web. Code Verify will immediately alert you if your web version is inauthentic or has been modified. NEED FOR WEB TRANSPARENCY Mobile phones have security verification protocols in place to ensure that the client you’re downloading is authentic and hasn’t been modified. Unfortunately, those assurances haven’t existed for web-based implementations of apps (those that run on web browsers). Code Verify was created as a solution. When people use messaging apps via the web, they’re being served Javascript rather than a binary application. This means it's technically possible to serve people a different experience than what they were expecting. We know that bad actors may want to alter an app and distribute that app to unsuspecting targets. For example, a bad actor could serve someone a version that was created to spy on them – without them ever knowing the difference. DESIGNED FOR SECURITY-CONSCIOUS USERS Code Verify was designed with our most security-conscious users in mind — those who might want additional peace of mind about their message security. Millions of people use WhatsApp, Facebook, Instagram, and Messenger on the web each month, and this type of independent verification and redundancy (also known as binary transparency) on the web is a huge step forward for online privacy. HOW DOES IT WORK? We've partnered with Cloudflare, a secure web content delivery service, to enable us to verify that everyone using WhatsApp, Facebook, Instagram, and Messenger on the web is accessing the same code, and we built a browser extension for you to independently verify that's the case. The Code Verify browser extension brings the same protections that mobile apps have to the web. The extension scans the Javascript code of the web-based app and ensures it matches the source of truth that has been publicly posted on Cloudflare. If there are inconsistencies, the extension will immediately alert you. When the WhatsApp, Facebook, Instagram, or Messenger clients are updated, the extension will also automatically update with a new source of truth so people are continuously assured that the version they’re running is the same version that other users are running. BENEFITS OF OPEN SOURCING We’re not just doing this for WhatsApp, Facebook, Instagram, and Messenger. Open sourcing the Code Verify extension means that other companies will be able to apply web binary transparency to their web-based apps as well. As a browser extension that is independent of Meta products and their infrastructure, people can be assured that the extension itself hasn’t been secretly modified by third parties. Since the extension exists in the public eye, it will be more difficult to modify it for any sort of nefarious purpose without people noticing. Now you can have the power of transparency directly in your hands. Use the Code Verify extension to provide confidence that the web app you’re using is authentic. Learn more about Code Verify at <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/cb4a6b557fdb099db78feb4dcd799d2a1d18bfedec941e56cad1f9580f615bbf/https%3A//faq.whatsapp.com/web/security-and-privacy/about-code-verify" rel="nofollow">https://faq.whatsapp.com/web/security-and-privacy/about-code-verify</a> <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/ed296d8b4dae71d68dacb998281b084a97611755d2349ac6bfea78ed4e3b4df8/https%3A//www.facebook.com/help/728172628487328" rel="nofollow">https://www.facebook.com/help/728172628487328</a> <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/eb3fb01c54b2a853706bdfec3799aeac5d08089500b52693b1265933e074e53f/https%3A//www.messenger.com/help/799550494558955" rel="nofollow">https://www.messenger.com/help/799550494558955</a> By downloading or using this extension, you agree to Meta’s terms of service available at <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/df5b299eeb1e10c07500ad7d886d59b91c22ee9b85e4d6dfacfbc7d9de5cb439/https%3A//www.facebook.com/terms.php" rel="nofollow">https://www.facebook.com/terms.php</a>. Learn how your data is processed for this extension by visiting the Meta Data Policy: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/baea8696d7d5a81cb841b062c34ad4ff2f3f88b80cf1b60118fb646bf5dada28/https%3A//www.facebook.com/about/privacy/" rel="nofollow">https://www.facebook.com/about/privacy/</a>.

Frequently Asked Questions