Microsoft Edge Add-ons Verified

AI Grammar Checker & Paraphraser – LanguageTool

c08f9592-899d-53de-b5ff-c3864f767988 | v11.4.0
65/ 100
MEDIUM risk
No change since v11.2.3
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (65/100) still counts them.

Analysis record

Analysed
1 weeks ago
Version
v11.4.0
Artifact
SHA256 F90…942
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

476 detail rows
Showing 25 of 476 · highest severity first

Publisher Evidence

Limited evidence

LanguageTool

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

47
Noisy-finding weight
x1.00
Publisher domain
languagetool.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
5
Portfolio

12 evidence rows available.

Finding Categories

51
Obfuscation
24
Network

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality weak.

This extension identifies itself as AI Grammar Checker & Paraphraser – LanguageTool, matching the legitimate LanguageTool service. The evidence contains no malware signatures. The overwhelming majority of findings are IoC entries that are not real domains. For example, XIOC-DOMAIN-lt-menu-overlay.lt, XIOC-DOMAIN-div.ms, XIOC-DOMAIN-div.docs, XIOC-DOMAIN-s.ht, XIOC-DOMAIN-e.site, XIOC-DOMAIN-gm.smart, XIOC-DOMAIN-嚸.ir, and XIOC-DOMAIN-φ.ua are fragments of property access chains, CSS selectors, or Unicode characters in minified JavaScript, not network destinations. XIOC-DOMAIN-gmx.net and XIOC-DOMAIN-atlassian.net are real third-party domains but are not suspicious in this context; gmx.net is a well-known email provider and atlassian.net is a legitimate SaaS domain. The only URL that points to an actual service is XIOC-URL-https://languagetool.org/?utm_campaign=addon2-popup-logo, which is the extension's own website with a campaign tracking parameter.

The network category contains a single fetch call in changelog/changelog.js:24. The finding does not identify a destination domain, so it provides no evidence of data exfiltration. A changelog file fetching its own update notes is normal behavior for an extension that displays release information.

The 46 obfuscation findings are consistent with minified production JavaScript, which is standard for browser extensions and does not by itself indicate concealment. The 326 code-smell findings are generic JavaScript patterns that fire on almost any non-trivial codebase and are not evidence of malicious intent.

A skeptic might argue that 1,577 total findings, an empty developer name, and 46 obfuscation findings are red flags. However, the IoC volume is driven by the XIOC extractor's known tendency to misread property access chains as domains. The empty developer name on the Edge store is not unusual for extensions published under a brand name, and the extension's name and description match the well-known LanguageTool service. No malware signatures matched, and no suspicious network destination appears anywhere in the findings. The evidence is consistent with a legitimate grammar checker whose bundled code triggers high-volume false positives.

Key Reasons

  • No malware signatures matched in any scanned file.
  • The 782 IoC findings are almost entirely malformed domain strings from property access chains and CSS selectors, not real network destinations.
  • The only real URL identified is the extension's own languagetool.org with a UTM campaign parameter.
  • The single network finding in changelog/changelog.js:24 does not identify a destination domain and is consistent with fetching a changelog.
  • The extension name and description match the well-known LanguageTool grammar checker service.

False Positive Considerations

  • XIOC extractor misreads property access chains and CSS selectors as domains (e.g., lt-menu-overlay.lt, div.ms, div.docs, s.ht, e.site, gm.smart).
  • Minified/bundled JavaScript triggers obfuscation findings without any accompanying malware signatures.
  • Code-smell findings (326) are generic JavaScript patterns and do not indicate malicious behavior.
  • No malware signatures or suspicious network destinations are present.

Reviewed 2026-09-05; recommended action: suppress false positive; model confidence 90%.

Edge version history

Risk trend by version

4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
65
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
11.0.0
May 6, 2026
Risk range
65 to 65
Across analyzed versions
Latest analyzed version
11.4.0
Sep 22, 2026
Selected version
medium
Version
v11.4.0
1 weeks ago
Risk score
65
Findings
476
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

Frequently Asked Questions