My Jobscore
The AI review rates the findings as likely false positive, but the risk score (88/100) still counts them.
Analysis record
- Analysed
- 2 weeks ago
- Version
- v1.5.15
- Artifact
- SHA256 295…F57
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
1 rule| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | supply chain sourcemap appended iife | 12 | widget-frame.jscomponents/hkt/index.jsutils/rtlUtils.js +9 more | - |
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
11 evidence rows available.
Finding Categories
YARA Rules Matched
1 rule(12 hits)Requested Permissions
7 permissionsAI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
The 'My Jobscore' extension (version 1.5.3) presents no evidence of malicious behavior despite a high total finding count of 4296. The extension's name and description ('My Jobscore Chrome Extension') indicate a legitimate job-related utility, and the developer attribution ([email protected]) follows standard practices for independent developers.
The 3652 IoC findings are driven by known XIOC extractor false positive patterns. Only one specific domain appears in the evidence: queue.jobs.map from the finding 'XIOC-DOMAIN-queue.jobs.map'. This domain name is consistent with legitimate application infrastructure for a job-related service, not the typical suspicious domains seen in browser hijacking or data exfiltration (e.g., query., search., or unknown tracking domains). The remaining 3651 IoCs are almost certainly garbage matches—IPv6 fragments, property access chains, and CDN domains that the extractor incorrectly identifies as indicators.
The 632 code-smell findings are all low-severity and match documented false positive patterns. These include rules like postinstall_* (matching basic Node.js patterns), credential_* (matching API key references), and code-quality rules. None of these constitute evidence of malicious intent, and the schema explicitly classifies these as 'code-smell/low' findings that should not drive verdicts.
Network findings show 11 websocket and fetch calls across files like js/wild_parser/websocket-service.js, js/wild_parser/ParserRuleStorage.js, and jsForEm/wild_parser/frame-coordinator.js. These are consistent with legitimate application functionality for a job search extension that needs to communicate with backend services. No suspicious external domains appear in these network findings.
The single manifest finding ('MANIFEST-SENSITIVE-PERM-TABS') indicates the extension requests the tabs permission, which is standard for extensions that need to interact with web pages—particularly relevant for a job-related tool that may need to parse job listings on employer websites.
Strongest counterargument: A skeptic could argue that 4296 total findings with 3652 IoCs represents significant risk. This reasoning is incorrect because finding COUNT is not evidence—finding NATURE is evidence. The scoring system has documented biases where confirmed false positives average risk scores of 83.2 due to IoC volume inflation. Zero malware signatures, zero obfuscation findings, and the absence of any specific suspicious domains demonstrate these findings are noise, not threats. The extension shows none of the high-confidence threat indicators: no typosquatting, no browser hijacking domains, no credential theft patterns, no malware delivery mechanisms, and no proxyware functionality.
Key Reasons
- Zero malware signatures detected
- Zero obfuscation findings
- 3652 IoC findings driven by known XIOC false positive patterns
- Single domain (queue.jobs.map) is consistent with legitimate infrastructure
- 632 code-smell findings are low-severity and match documented FP patterns
False Positive Considerations
- XIOC extractor garbage (3652 IoCs with only 1 specific domain)
- Low-severity code-smell rules (632 findings)
- Bundled dependency patterns in network calls
- Score inflation from finding volume
Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.
Chrome version history
Risk trend by version
4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Jobseeker - Maryland
[email protected]
Edge Translate - Browser Translator | PDF Translation | MV3 | Open Source
[email protected]
Intelbras Cloud
[email protected]
SlingPlayer for DISH Anywhere
Unknown Developer
种草星球-TikTok爆单神器,商品自动提报采集邀评【永久免费】
[email protected]
Kindredly - A safer, private web for families
[email protected]