Patreon Easy Downloader
The AI review rates the findings as likely false positive, but the risk score (85/100) still counts them.
Analysis record
- Analysed
- 2 days ago
- Version
- v326
- Artifact
- SHA256 9CB…0A2
- Source
- Findings (non-IoC)
Is Patreon Easy Downloader safe?
Patreon Easy Downloader organizes and downloads media from Patreon creators you support. The extension's manifest lists no special permissions, and it declares no external network endpoints of its own, so nothing in the listing shows it reaching a server that is not Patreon.
The scan returned four medium-severity findings and no malware signatures. Two of them, NET-FETCH-js/background.js-1 and NET-FETCH-js/shared.js-1, are triggered by the fetch calls a downloader needs to retrieve files. That check fires on any script that makes a network request, and both hits land at line 1 of their files, which is where a bundled file starts rather than a spot inside the logic. The third, OBFUSCATION-FUNCTION_INDIRECT-js/options.js-1, flags a function called through a variable in the options page, which is how a settings screen wires up its buttons and toggles. The fourth is a manifest observation with no detail attached.
None of that describes the extension misbehaving. Calling fetch, or invoking a function through a variable, is ordinary in an extension that downloads files, and no outbound domain, cookie read or encrypted payload turned up anywhere in the code. The one thing worth watching is that the manifest permission list came back empty, which is unusual for a downloader and likely means the listing was only partly read.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
Limited evidenceCosmious
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
Requested Permissions
16 permissionsManage, modify, and monitor downloads
Access your identity and sign-in tokens
Read and modify cookies on all sites
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
Patreon Easy Downloader does one job: it pulls media from Patreon pages you are already signed into and files it locally. The extension lists no permissions, no host permissions and no network endpoints of its own. Four medium-severity findings came back, and none of them is a malware signature, an indicator of compromise, a secret or a code-smell hit. Two are network flags in js/background.js and js/shared.js, one is a function-indirection flag in js/options.js, and the fourth is a manifest-level observation with no detail attached.
The NET-FETCH findings in js/background.js and js/shared.js fire when a script calls fetch or XMLHttpRequest. A downloader whose entire purpose is retrieving files from Patreon has to make network calls, so this rule describes the extension's core function. Both hits sit at line 1 of their files, the point where a bundled or entry file begins, which means the scanner flagged the top of the module rather than a specific payload inside it. The IoC extractor returned nothing at all from these files: no domain, IP or URL was pulled out of the code and tied to those calls. If the extension were shipping data to an outside server, that is exactly where it would show up.
The OBFUSCATION-FUNCTION_INDIRECT hit in js/options.js flags a function that gets invoked through a variable rather than by a literal name. That pattern shows up in any settings screen that builds click handlers from a table of options, and options.js is the options page. There is no string encryption, no eval, no packed or encoded blob anywhere in the findings. Bundled dependencies produced no findings either, so this is not a case of dist/ noise inflating the numbers.
A skeptic would point at two things. The publisher name, Cosmious, is a lone handle, and version 326 suggests a long-lived project maintained by one person rather than a company. More pointedly, the manifest came back with an empty permission list, which is odd for something that downloads files, and the single manifest-analysis finding carries no description. Either the manifest was only partly parsed or the extension relies on content scripts that the extractor did not capture. That gap is real, and it is a completeness problem, not evidence of harm. Nothing in the findings touches cookies, sessions, credentials or login domains, and there is no external endpoint to check.
What would change this read is concrete: an outbound domain that is not Patreon, a cookie or session access, an encrypted payload, or a fetch target hidden behind string construction. None of those appear. The checks that did fire describe code shapes that any downloader extension has to have.
Key Reasons
- All four findings are medium-severity heuristics; zero IoCs, malware signatures, secrets or dependency findings were returned
- NET-FETCH-js/background.js-1 and NET-FETCH-js/shared.js-1 flag the fetch calls a downloader needs, at line 1 of each bundled file
- OBFUSCATION-FUNCTION_INDIRECT-js/options.js-1 describes variable-based function dispatch, standard in an options page
- Empty permission and host_permission lists with no declared network endpoints leave no suspicious destination to investigate
- Extension has a description, a named publisher and 1,688 users, with no impersonation of a known brand
False Positive Considerations
- NET-FETCH heuristic fires on any script using fetch or XMLHttpRequest, which every downloader does
- OBFUSCATION-FUNCTION_INDIRECT matches routine callback and dispatch patterns in a settings UI
- Hits reported at line 1 of bundled files rather than at specific payload locations
- No IoCs extracted, so the network findings name no actual domain or endpoint
Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 80%.
Firefox version history
Risk trend by version
22 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
VaultysHub extension
Vaultys
Kindredly - A safer, private web for families
Kindredly.ai
Malwarebytes Browser Guard
Malwarebytes
VHS - Dev Tools
Vihat Software
Ultimate New Tab Page - AI Search & Dial
Dracon
General Sticker System (GSS)
ElfinL