Chrome Web Store Verified

Cisco Web Communicator

by [email protected] · 10.0K users · 1.0 rating
e5f2cec9-8fad-5cc7-9705-35414e534723 | v11.8.4.1
0/ 100
MINIMAL risk
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
10 months ago
Version
v11.8.4.1
Artifact
SHA256 EE2…A12
Source
Findings (non-IoC)

No Findings

All security checks passed

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

62
Noisy-finding weight
x1.00
Publisher domain
cisco.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
24
Portfolio

12 evidence rows available.

No Threats Detected

This extension passed all security checks

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

The Cisco Web Communicator extension has triggered several YARA rule matches related to postinstall system commands, crypto operations, network communication, and file manipulation. However, these findings are all categorized as code-smell and are likely false positives due to the nature of the YARA rules. The postinstall_* rules are known to match basic Node.js patterns and are not indicative of malicious behavior. The extension also declares the 'nativemessaging' permission in its manifest, which is potentially sensitive but not necessarily malicious. A network call of type 'xmlhttprequest' is detected in the cwic_plugin.js file, but this is a common and legitimate practice. The strongest counterargument to this verdict would be that the extension's code is overly permissive and could be exploited by an attacker. However, given the lack of any specific malware signatures or suspicious domains, it is more likely that the extension is simply a powerful tool that requires careful handling. The developer, Cisco, is a known and reputable entity, which further supports the conclusion that this extension is not malicious. The findings are largely driven by known false-positive patterns, and the extension's capabilities are consistent with its intended purpose of enabling Cisco Jabber phone and video calls.

Key Reasons

  • YARA code-smell rules triggered
  • No malware signatures or suspicious domains found
  • Extension capabilities consistent with intended purpose

False Positive Considerations

  • YARA code-smell rules
  • IoC extractor garbage

Reviewed 2026-05-23; recommended action: no action; model confidence 80%.

About This Extension

Enable Web applications integrated with Cisco Jabber voice and video to use the Cisco Web Communicator add-on. Install this extension to enable Cisco Jabber voice and video, or control of Cisco phones, from within Web applications integrated by Cisco partners or customers into Cisco Unified Communications environments. Used in conjunction with the Cisco Web Communicator add-on (provided separately after this extension is installed, or by your system administrator), this extension enables you to place and receive voice and video calls in your Chrome browser, or using an integrated Cisco phone on your desk. This extension supports Cisco Web Communicator 11.8.4.1 and later. For support, please use the support mechanism provided for the Web application providing integrated Cisco voice and video softphone, or phone control. IMPORTANT NOTICES AND DISCLAIMERS - PLEASE READ END USER LICENSE AGREEMENT Use of this Software is governed by the Cisco End User License Agreement. http://www.cisco.com/go/eula CISCO PRIVACY STATEMENT http://www.cisco.com/web/siteassets/legal/privacy_full.html STRONG ENCRYPTION NOTICE This product contains cryptographic features and is subject to United States and local country laws governing import, export, transfer and use. Delivery of Cisco cryptographic products does not imply third-party authority to import, export, distribute or use encryption. Importers, exporters, distributors and users are responsible for compliance with U.S. and local country laws. By using this product you agree to comply with applicable laws and regulations. If you are unable to comply with U.S. and local laws, return this product immediately. A summary of U.S. laws governing Cisco cryptographic products may be found at: http://www.cisco.com/wwl/export/crypto/tool/stqrg.html If you require further assistance concerning the exporting of these products, please contact us by sending email to [email protected]. COPYRIGHT NOTICE Copyright 2025 Cisco Systems, Inc. All Rights Reserved.

Frequently Asked Questions