Microsoft Edge Add-ons Verified

InTab

d59b1f21-946c-5795-9695-d819205d6937 | v4.2.3
65/ 100
MEDIUM risk
No change since v4.2.2
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (65/100) still counts them.

Analysis record

Analysed
Today
Version
v4.2.3
Artifact
SHA256 B86…533
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

556 detail rows
Showing 25 of 556 · highest severity first

Publisher Evidence

Limited evidence

intab.io

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

42
Noisy-finding weight
x1.00
Publisher domain
intab.io
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
4
Portfolio

12 evidence rows available.

Finding Categories

23
Obfuscation
57
Network

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

The extension "InTab - Style Websites Faster" from developer "Raya.io" presents a confusing security profile that resolves upon examining finding types. The findings summary reports 26 high-severity malware-signature findings but zero actual malware detections (malware: 0), zero IoCs (ioc: 0), and zero obfuscation indicators (obfuscation: 0). This discrepancy strongly indicates the malware signatures are false positives from overly broad YARA rules rather than actual malicious code.

The single network finding in back-08397916a9.js:1 (title: "NET-FETCH-back-08397916a9.js-1") represents a standard fetch call, which is expected behavior for a styling extension that may need to retrieve configuration or style data. No suspicious domains appear in the network findings, and the severity is only medium.

The 74 info-level metadata findings are hash signatures for CSS and SVG asset files (e.g., app-401feb97a7.css, asset/svg/cell-f0b97d4a30.svg, asset/svg/row-60f6e85f8b.svg), which are benign and expected for any extension with visual assets. These do not indicate malicious behavior.

Counterargument: A skeptic might argue that 26 high-severity malware signatures cannot be dismissed as noise. However, malware signatures without corresponding IoCs, obfuscation, or actual malware detection are characteristic of broad YARA rules matching benign code patterns. Known false positive patterns include Bolonyokte (matches "Online Banking"/"login" strings), JavaDropper (matches config.ini references), and Surtr (matches generic DLL names). The extension's legitimate purpose (website styling), named developer attribution (Raya.io), and lack of suspicious network behavior all support the false positive hypothesis. If these were genuine malware signatures, we would expect to see suspicious domains in IoCs, obfuscation techniques, or actual malware detection.

The "unknown" version field and zero user count limit contextual assessment, but the scan itself produced complete results. The nature of findings—not their count—determines this verdict.

Key Reasons

  • 26 malware-signature findings with zero actual malware detection indicates YARA false positives
  • Zero IoCs and zero obfuscation findings contradicts malicious behavior
  • Single network finding is benign fetch call in back-08397916a9.js
  • Named developer attribution (Raya.io) provides credibility
  • Extension description matches legitimate styling functionality

False Positive Considerations

  • Malware-signature false positives from broad YARA rules
  • Bundled dependencies triggering YARA matches
  • Minified code patterns matching generic rules

Reviewed 2026-05-04; recommended action: suppress false positive; model confidence 70%.

Edge version history

Risk trend by version

4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
65
Change since first
+19
Change from previous
No change
Versions:
First analyzed version
2.9.71
Apr 4, 2026
Risk range
46 to 75
Across analyzed versions
Latest analyzed version
4.2.3
Oct 1, 2026
Selected version
medium
Version
v4.2.3
Today
Risk score
65
Findings
556
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

Frequently Asked Questions