AI Grammar Checker & Paraphraser – LanguageTool
The AI review rates the findings as likely false positive, but the risk score (65/100) still counts them.
Analysis record
- Analysed
- 1 weeks ago
- Version
- v11.4.0
- Artifact
- SHA256 F90…942
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
Limited evidenceLanguageTool
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality weak.
This extension identifies itself as AI Grammar Checker & Paraphraser – LanguageTool, matching the legitimate LanguageTool service. The evidence contains no malware signatures. The overwhelming majority of findings are IoC entries that are not real domains. For example, XIOC-DOMAIN-lt-menu-overlay.lt, XIOC-DOMAIN-div.ms, XIOC-DOMAIN-div.docs, XIOC-DOMAIN-s.ht, XIOC-DOMAIN-e.site, XIOC-DOMAIN-gm.smart, XIOC-DOMAIN-嚸.ir, and XIOC-DOMAIN-φ.ua are fragments of property access chains, CSS selectors, or Unicode characters in minified JavaScript, not network destinations. XIOC-DOMAIN-gmx.net and XIOC-DOMAIN-atlassian.net are real third-party domains but are not suspicious in this context; gmx.net is a well-known email provider and atlassian.net is a legitimate SaaS domain. The only URL that points to an actual service is XIOC-URL-https://languagetool.org/?utm_campaign=addon2-popup-logo, which is the extension's own website with a campaign tracking parameter.
The network category contains a single fetch call in changelog/changelog.js:24. The finding does not identify a destination domain, so it provides no evidence of data exfiltration. A changelog file fetching its own update notes is normal behavior for an extension that displays release information.
The 46 obfuscation findings are consistent with minified production JavaScript, which is standard for browser extensions and does not by itself indicate concealment. The 326 code-smell findings are generic JavaScript patterns that fire on almost any non-trivial codebase and are not evidence of malicious intent.
A skeptic might argue that 1,577 total findings, an empty developer name, and 46 obfuscation findings are red flags. However, the IoC volume is driven by the XIOC extractor's known tendency to misread property access chains as domains. The empty developer name on the Edge store is not unusual for extensions published under a brand name, and the extension's name and description match the well-known LanguageTool service. No malware signatures matched, and no suspicious network destination appears anywhere in the findings. The evidence is consistent with a legitimate grammar checker whose bundled code triggers high-volume false positives.
Key Reasons
- No malware signatures matched in any scanned file.
- The 782 IoC findings are almost entirely malformed domain strings from property access chains and CSS selectors, not real network destinations.
- The only real URL identified is the extension's own languagetool.org with a UTM campaign parameter.
- The single network finding in changelog/changelog.js:24 does not identify a destination domain and is consistent with fetching a changelog.
- The extension name and description match the well-known LanguageTool grammar checker service.
False Positive Considerations
- XIOC extractor misreads property access chains and CSS selectors as domains (e.g., lt-menu-overlay.lt, div.ms, div.docs, s.ht, e.site, gm.smart).
- Minified/bundled JavaScript triggers obfuscation findings without any accompanying malware signatures.
- Code-smell findings (326) are generic JavaScript patterns and do not indicate malicious behavior.
- No malware signatures or suspicious network destinations are present.
Reviewed 2026-09-05; recommended action: suppress false positive; model confidence 90%.
Edge version history
Risk trend by version
4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace