Cisco Web Communicator
Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 10 months ago
- Version
- v11.8.4.1
- Artifact
- SHA256 EE2…A12
- Source
- Findings (non-IoC)
No Findings
All security checks passed
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
No Threats Detected
This extension passed all security checks
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
The Cisco Web Communicator extension has triggered several YARA rule matches related to postinstall system commands, crypto operations, network communication, and file manipulation. However, these findings are all categorized as code-smell and are likely false positives due to the nature of the YARA rules. The postinstall_* rules are known to match basic Node.js patterns and are not indicative of malicious behavior. The extension also declares the 'nativemessaging' permission in its manifest, which is potentially sensitive but not necessarily malicious. A network call of type 'xmlhttprequest' is detected in the cwic_plugin.js file, but this is a common and legitimate practice. The strongest counterargument to this verdict would be that the extension's code is overly permissive and could be exploited by an attacker. However, given the lack of any specific malware signatures or suspicious domains, it is more likely that the extension is simply a powerful tool that requires careful handling. The developer, Cisco, is a known and reputable entity, which further supports the conclusion that this extension is not malicious. The findings are largely driven by known false-positive patterns, and the extension's capabilities are consistent with its intended purpose of enabling Cisco Jabber phone and video calls.
Key Reasons
- YARA code-smell rules triggered
- No malware signatures or suspicious domains found
- Extension capabilities consistent with intended purpose
False Positive Considerations
- YARA code-smell rules
- IoC extractor garbage
Reviewed 2026-05-23; recommended action: no action; model confidence 80%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Webex Calling for Chrome
[email protected]
Call with Jabber
[email protected]
Cisco Webex Extension
[email protected]
Edge Translate - Browser Translator | PDF Translation | MV3 | Open Source
[email protected]
Intelbras Cloud
[email protected]
SlingPlayer for DISH Anywhere
Unknown Developer