The AI review rates the findings as likely false positive, but the risk score (65/100) still counts them.
Analysis record
- Analysed
- Today
- Version
- v4.2.3
- Artifact
- SHA256 B86…533
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
Limited evidenceintab.io
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
The extension "InTab - Style Websites Faster" from developer "Raya.io" presents a confusing security profile that resolves upon examining finding types. The findings summary reports 26 high-severity malware-signature findings but zero actual malware detections (malware: 0), zero IoCs (ioc: 0), and zero obfuscation indicators (obfuscation: 0). This discrepancy strongly indicates the malware signatures are false positives from overly broad YARA rules rather than actual malicious code.
The single network finding in back-08397916a9.js:1 (title: "NET-FETCH-back-08397916a9.js-1") represents a standard fetch call, which is expected behavior for a styling extension that may need to retrieve configuration or style data. No suspicious domains appear in the network findings, and the severity is only medium.
The 74 info-level metadata findings are hash signatures for CSS and SVG asset files (e.g., app-401feb97a7.css, asset/svg/cell-f0b97d4a30.svg, asset/svg/row-60f6e85f8b.svg), which are benign and expected for any extension with visual assets. These do not indicate malicious behavior.
Counterargument: A skeptic might argue that 26 high-severity malware signatures cannot be dismissed as noise. However, malware signatures without corresponding IoCs, obfuscation, or actual malware detection are characteristic of broad YARA rules matching benign code patterns. Known false positive patterns include Bolonyokte (matches "Online Banking"/"login" strings), JavaDropper (matches config.ini references), and Surtr (matches generic DLL names). The extension's legitimate purpose (website styling), named developer attribution (Raya.io), and lack of suspicious network behavior all support the false positive hypothesis. If these were genuine malware signatures, we would expect to see suspicious domains in IoCs, obfuscation techniques, or actual malware detection.
The "unknown" version field and zero user count limit contextual assessment, but the scan itself produced complete results. The nature of findings—not their count—determines this verdict.
Key Reasons
- 26 malware-signature findings with zero actual malware detection indicates YARA false positives
- Zero IoCs and zero obfuscation findings contradicts malicious behavior
- Single network finding is benign fetch call in back-08397916a9.js
- Named developer attribution (Raya.io) provides credibility
- Extension description matches legitimate styling functionality
False Positive Considerations
- Malware-signature false positives from broad YARA rules
- Bundled dependencies triggering YARA matches
- Minified code patterns matching generic rules
Reviewed 2026-05-04; recommended action: suppress false positive; model confidence 70%.
Edge version history
Risk trend by version
4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace