Firefox Add-ons Verified

Extension

by DuckDuckGo · 34.0K users · 4.0 rating
dceec4f9-c3ac-50f9-a700-b98e24f24fc8 | v2026.7.9
60/ 100
MEDIUM risk
+3 since v2026.6.5
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (60/100) still counts them.

Analysis record

Analysed
2 weeks ago
Version
v2026.7.9
Artifact
SHA256 3EE…7D7
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

9 detail rows

YARA Rule Matches

5 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall file manipulation 1
background.js
-
LOWpostinstall environment access 1
background.js
-
LOWpostinstall network communication 1
background.js
-
LOWpostinstall file download 1
background.js
-
LOWNoUseWeakRandom 1
background.js
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

12 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

DuckDuckGo

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

38
Noisy-finding weight
x1.00
Publisher domain
noai.duckduckgo.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

3
Network
12
IoC Indicators

YARA Rules Matched

5 rules
postinstall file manipulation postinstall environment access postinstall network communication postinstall file download NoUseWeakRandom

Requested Permissions

6 permissions
webRequest

Intercept, modify, and block all network requests

High
tabs
Medium
declarativeNetRequest
Low
storage
Low
https://duckduckgo.com/*
Low
https://*.duckduckgo.com/*
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

This extension's findings are overwhelmingly consistent with legitimate DuckDuckGo search functionality. All 20 IoC findings reference DuckDuckGo domains: https://duckduckgo.com/atb.js?$, https://noai.duckduckgo.com/?q=, https://noai.duckduckgo.com/ac/?q=, and [email protected]. These domains directly align with the extension's description: "Search privately by default, without AI features." The noai.duckduckgo.com subdomain appears to be DuckDuckGo's official endpoint for their non-AI search mode.

The 3 network findings in background.js:90 and background.js:122 show fetch calls, which is expected behavior for a search extension that must communicate with search engines. There are zero malware signatures, zero obfuscation findings, and zero code-smell findings. The single MD5 hash IoC (a0932ba6b7f91d3b104aac62bb188098) has no associated malware classification.

The strongest counterargument to this verdict is the empty extension name and empty developer_name field, combined with a future version number (2026.4.24) and very low user count (4). These metadata anomalies could indicate an unverified or test extension. However, metadata gaps alone do not constitute evidence of malicious behavior. The technical findings—specifically the absence of malware signatures, obfuscation, or suspicious third-party domains—provide stronger evidence about the extension's actual behavior than metadata completeness. The IoC volume is driven by the XIOC extractor flagging legitimate DuckDuckGo infrastructure, a known false-positive pattern when extensions use well-known service domains.

The extension appears to be a DuckDuckGo search tool with proper integration to their infrastructure. The findings are noise from the IoC extractor, not indicators of compromise.

Key Reasons

  • All 20 IoC findings reference legitimate DuckDuckGo domains matching extension purpose
  • Zero malware signatures detected
  • Zero obfuscation findings
  • Zero code-smell findings
  • Network activity in background.js consistent with search extension functionality

False Positive Considerations

  • IoC extractor flagging legitimate DuckDuckGo service domains
  • Fetch calls in background.js are expected for search extensions
  • MD5 hash IoC without malware classification

Reviewed 2026-05-07; recommended action: no action; model confidence 72%.

Firefox version history

Risk trend by version

3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
60
Change since first
+3
Change from previous
+3
Versions:
First analyzed version
2026.4.24
May 7, 2026
Risk range
57 to 60
Across analyzed versions
Latest analyzed version
2026.7.9
Jul 17, 2026
Selected version
medium
Version
v2026.7.9
2 months ago
Risk score
60
Findings
21
Change vs previous
+3

Pick any point on the chart to explore that version's code below.

Frequently Asked Questions