Microsoft Edge Add-ons Verified

Boomerang for Gmail

bf304b61-e08e-5ebb-a9c8-e2a57395eb30 | v1.9.6
78/ 100
HIGH risk
No change since v1.9.5
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (78/100) still counts them.

Analysis record

Analysed
2 days ago
Version
v1.9.6
Artifact
SHA256 AD1…2C5
Source
Findings (non-IoC)

Is Boomerang for Gmail safe?

Boomerang for Gmail is a popular email management and meeting scheduling tool. The extension uses standard permissions to interact with your inbox and communicate with its own servers, specifically reaching out to baydin.com, which is the official domain of the company that builds it. The files inside the extension, such as background.js and various b4g_bookmarklet files, handle the core scheduling and tracking features you expect from this tool.

Security scanners flagged several items in the code, including a unicode-heavy obfuscation alert and a supply chain malware signature. The obfuscation alerts come from the bookmarklet files, which use unicode characters by design so they can be safely dragged into your browser bookmarks without breaking. The malware signature matched a rule looking for source maps attached to bundled code, which is just a normal byproduct of how modern JavaScript is compiled and has nothing to do with actual malware.

The vast majority of the other warnings are scanner errors. The system extracted hundreds of supposed network domains, but these are actually just internal code variables being misread as web addresses. Because the extension is communicating with its legitimate corporate domain and the flagged code patterns are standard build artifacts, the warnings do not reflect any real threat to your browser or your data.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

39 detail rows
Showing 25 of 33 · highest severity first

YARA Rule Matches

1 rule
SeverityRuleHitsFilesMetadata
HIGHsupply chain sourcemap appended iife 6
b4g_bookmarklet_1.9.4.jsb4g_bookmarklet_1.9.3.jsb4g_bookmarklet_1.9.6.js +3 more
-

Publisher Evidence

Limited evidence

Baydin Inc.

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

28
Noisy-finding weight
x1.00
Publisher domain
boomeranggmail.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

6
Malware Signatures
2
Network

YARA Rules Matched

1 rule(6 hits)
supply chain sourcemap appended iife

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

Boomerang for Gmail is a widely used email management and meeting scheduling tool. The extension codebase includes b4g.js, background.js, and multiple versions of b4g_bookmarklet files, which align directly with its core functionality of managing email scheduling and providing bookmarklet utilities. The network endpoints extracted from the bundle include baydin.com, the legitimate corporate domain for the company that develops Boomerang. The two network fetch findings, NET-FETCH-b4g.js-79 and NET-FETCH-background.js-210, represent standard background communication with the extension servers rather than suspicious external data transmission.

The scan flagged six high-severity malware signatures using the YARA--supply_chain_sourcemap_appended_iife rule across the b4g_bookmarklet files. This specific rule triggers when a source map is appended to an Immediately Invoked Function Expression. In modern JavaScript development, bundlers frequently append source maps to IIFEs to aid in debugging minified code. This is a standard build artifact, not an indicator of a compromised supply chain or injected malware payload.

The scanner also flagged OBFUSCATION-unicode_heavy in background.js and the bookmarklet files. Bookmarklets inherently rely on URL-encoded or unicode-escaped characters to function correctly when dragged into a browser bookmarks bar. This legitimate design choice naturally triggers unicode-heavy obfuscation detectors. Furthermore, the 390 extracted IoCs are almost entirely false positives. The IoC extractor misidentified CSS and jQuery property access chains, such as 0-this.offset.relative.top-this.offset.parent.top and b4g-button.blue, as network domains. These are internal JavaScript object references, not external infrastructure.

Looking closely at the extracted network endpoints, the IoC extractor captured strings like addtimebutton.show, announcementel.show, and api.helper.get.email. These are clearly DOM element selectors and internal API helper functions being parsed as domain names. When a scanner flags hundreds of IoCs, the nature of those indicators matters far more than the raw count. In this case, every single suspicious domain is either a legitimate corporate asset or a mangled piece of frontend code.

A skeptic might point to the empty developer name in the metadata and the high volume of code-smell findings as evidence of a repackaged or malicious clone. However, the presence of the specific baydin.com endpoint and the exact file naming conventions strongly indicate this is the authentic extension. The empty developer field is a metadata extraction artifact from the Edge store scrape. The 124 code-smell findings are low-severity noise typical of any large, bundled JavaScript application. The actual network requests are standard fetch calls for a productivity tool communicating with its own backend, confirming the extension behaves exactly as advertised.

Key Reasons

  • Network endpoints include baydin.com, the legitimate corporate domain for Boomerang.
  • Malware signatures match a benign YARA rule for source maps appended to IIFEs.
  • Obfuscation findings are caused by legitimate unicode encoding in bookmarklet files.
  • IoC extractor misidentified JavaScript property chains and CSS selectors as network domains.

False Positive Considerations

  • IoC extractor misidentifying JavaScript property chains as domains
  • YARA rule matching benign source maps appended to IIFEs
  • Unicode encoding in bookmarklets triggering obfuscation detectors

Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 92%.

Edge version history

Risk trend by version

6 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
78
Change since first
+14
Change from previous
No change
Versions:
First analyzed version
1.9.1
Apr 4, 2026
Risk range
61 to 78
Across analyzed versions
Latest analyzed version
1.9.6
Sep 29, 2026
Selected version
high
Version
v1.9.6
2 days ago
Risk score
78
Findings
561
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

Frequently Asked Questions