Code Verify
The AI review rates the findings as likely false positive, but the risk score (84/100) still counts them.
Analysis record
- Analysed
- 2 weeks ago
- Version
- v4.2.0
- Artifact
- SHA256 303…DE2
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
1 rule| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | supply chain sourcemap appended iife | 4 | contentFB.jscontentIG.jscontentWA.js +1 more | - |
Publisher Evidence
Limited evidenceMeta Extensions
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
YARA Rules Matched
1 rule(4 hits)Requested Permissions
10 permissionsIntercept, modify, and block all network requests
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
Code Verify (Firefox, v4.1.0) generates 267 total findings, but the evidence reveals these are false positives from known CVEQ noise patterns.
IoC findings are documentation references, not network destinations. All 204 IoC findings point to https://www.ecma-international.org/ecma-262/8.0/ paths such as XIOC-URL-https://www.ecma-international.org/ecma-262/8.0/#prod-annexB-IdentityEscape and XIOC-URL-https://www.ecma-international.org/ecma-262/8.0/#prod-CharacterClassEscape. These are JavaScript language specification documentation links embedded in code comments or strings. The XIOC extractor incorrectly parses these as suspicious URLs. This matches the documented false positive pattern where property access chains and documentation links trigger IoC matches.
Network findings are generic fetch calls without suspicious destinations. The 9 network findings show NET-FETCH-contentWA.js-185, NET-FETCH-contentFB.js-708, NET-FETCH-contentIG.js-708, NET-FETCH-contentMSGR.js-708, and NET-FETCH-background.js-627. These are standard JavaScript fetch() API calls. The file names (contentWA.js, contentFB.js, contentIG.js, contentMSGR.js) indicate content scripts for WhatsApp, Facebook, Instagram, and Messenger platforms. This naming pattern is consistent with a legitimate extension that interacts with social media sites for its stated purpose of code verification. No specific suspicious domains appear in these network findings.
Zero malware signatures eliminate confirmed malicious intent. The findings summary shows "malware-signature":"0" and "malware":"0". This is decisive evidence against malicious behavior. Real malware extensions trigger at least one malware family signature when combined with obfuscation or suspicious domains. This extension has neither.
Code-smell findings are noise. The 52 code-smell findings fire on standard JavaScript patterns. As documented in CVEQ guidelines, rules like postinstall_*, credential_*, and code-quality checks match almost any non-trivial JavaScript and should not drive verdicts.
The strongest counterargument is the empty developer name. A skeptic would argue that "developer_name": "" combined with 267 findings indicates a suspicious, anonymous publisher. However, the nature of the findings matters more than the count. The 204 IoC findings are documentation links, the 52 code-smell findings are noise, and the 9 network findings are generic fetch calls. The 2 obfuscation findings require inspection but without malware signatures or suspicious domains, they do not constitute evidence of malicious intent. Developer attribution is a weak signal compared to concrete behavioral evidence.
Verdict justification. This extension matches the "What is Almost Always Benign" profile: high IoC counts from documentation references, code-smell findings from standard JavaScript, and zero malware signatures. The extension name "Code Verify" and description "verify the code running in your browser matches what was published" align with the content script file names targeting social media platforms. Suppress this false positive.
Key Reasons
- All 204 IoC findings are ecma-international.org documentation URLs, not actual network destinations
- Zero malware signatures detected despite 267 total findings
- Network findings are generic fetch() calls without suspicious domains
- File naming (contentWA.js, contentFB.js, contentIG.js) matches stated purpose of social media code verification
- Code-smell findings are documented false positive noise
False Positive Considerations
- XIOC documentation URL extraction
- Generic fetch() API detection
- Code-smell rules on standard JavaScript
- Empty developer name (weak signal)
Reviewed 2026-04-29; recommended action: suppress false positive; model confidence 85%.
Firefox version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
VaultysHub extension
Vaultys
Kindredly - A safer, private web for families
Kindredly.ai
Malwarebytes Browser Guard
Malwarebytes
VHS - Dev Tools
Vihat Software
Ultimate New Tab Page - AI Search & Dial
Dracon
General Sticker System (GSS)
ElfinL