Microsoft Edge Add-ons Verified

StyleGuard Pro

f3ee8638-4adb-5eec-9899-2b28bdce5efa | v5.4.1.10
65/ 100
MEDIUM risk
No change since v5.4.1.9
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (65/100) still counts them.

Analysis record

Analysed
2 days ago
Version
v5.4.1.10
Artifact
SHA256 AD4…D86
Source
Findings (non-IoC)

Is StyleGuard Pro safe?

StyleGuard Pro is a writing assistant that checks grammar and style. The extension's code includes a tansaclient/ directory with files like tansa.js and googleDocsAdapter.js, which are part of Tansa's commercial proofreading software. The extension declares no special permissions, meaning it cannot access your browsing history or read page content without explicit interaction.

The security scan found 1085 items, but nearly all are false alarms. The 559 "IoC" findings are mostly JavaScript code fragments like bounds.bottom-viewport.top and btn-group.open that the scanner misidentified as web addresses. The 272 "code-smell" findings are low-level matches that trigger on any complex JavaScript code. The 9 obfuscation findings appear in the Tansa client code, which handles Unicode text processing and dynamic interface generation. None of these findings include actual malware signatures.

The verdict follows because the scanner tripped on known false positive patterns. The IoC extractor flagged property access chains and CSS class names as domains. The code-smell rules matched basic JavaScript patterns. The obfuscation detector flagged legitimate commercial code. Without malware signatures or suspicious network destinations, these findings don't indicate malicious behavior. The extension's lack of permissions further limits what it can do, even if someone wanted to misuse it.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

526 detail rows
Showing 25 of 254 · highest severity first

YARA Rule Matches

18 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall persistence mechanism 8
tansaclient/styles/css/nimbus-sans-l/fonts/NimbusSanL-Reg.ttftansaclient/js/lib/purify.min.jstansaclient/js/lib/bootstrap-4.0.0/js/bootstrap.bundle.js +5 more
-
LOWcredential env files 1
tansaclient/js/draft-js/javascript-draft.js
-
LOWLocalStorageShouldNotBeUsed 6
tansaclient/lingofy/login.htmltansaclient/scripts/gui.jstansaclient/tansaLoader.js +3 more
-
LOWDebuggerStatementsShouldNotBeUsed 1
tansaclient/js/draft-js/javascript-draft.js
-
LOWSQLInjection 11
tansaclient/js/lib/bootstrap-4.0.0/js/bootstrap.bundle.min.jstansaclient/js/lib/bootstrap-4.0.0/js/bootstrap.jsjs/jquery/jquery-2.1.1.min.js +8 more
-
LOWNoUseEval 7
tansaclient/scripts/lingofy/about.jstansaclient/scripts/lingofy/login.jstansaclient/js/slick-grid/slick.grid.js +4 more
-
LOWNoUseWeakRandom 20
tansaclient/scripts/jquery.jsjs/jquery/jquery-2.1.1.min.jstansaclient/js/lib/bootstrap-4.0.0/js/bootstrap.bundle.js.map +17 more
-
LOWpostinstall file download 14
js/jquery/jquery.blockUI.jstansaclient/js/draft-js/javascript-draft.jstansaclient/scripts/about.js +11 more
-
LOWUntrustedContentShouldNotBeIncluded 3
tansaclient/initGuiHTML_v1.jstansaclient/tansaLoader.jstansaclient/tansaDependencies.js
-
LOWpostinstall obfuscation 32
js/jquery/jquery-migrate-1.2.1.min.jstansaclient/styles/css/tansa/styles.csstansaclient/js/lib/bootstrap-4.0.0/js/bootstrap.bundle.js +29 more
-
LOWpostinstall system command 46
tansaclient/js/lib/bootstrap-4.0.0/js/bootstrap.js.maptansaclient/js/lib/bootstrap-4.0.0/css/bootstrap.csstansaclient/scripts/lingofy/login.js +43 more
-
LOWpostinstall crypto operations 14
tansaclient/scripts/gui.jstansaclient/js/lib/bootstrap-4.0.0/js/bootstrap.bundle.jstansaclient/scripts/jquery.js +11 more
-
LOWpostinstall file manipulation 60
tansaclient/initTansaLoader.jstansaclient/js/lib/bootstrap-4.0.0/js/bootstrap.bundle.jstansaclient/scripts/js/extenstions/client/tansa4ClientFigmaExtension.js +57 more
-
LOWpostinstall network communication 40
tansaclient/lingofy/login.htmltansaclient/styles/css/tansa/styles.cssmanifest.json +37 more
-
LOWOriginsNotVerified 5
tansaclient/lingofy/licenseIssue.htmltansaclient/scripts/js/extenstions/client/tansa4ClientFigmaExtension.jstansaclient/about.html +2 more
-
LOWpostinstall environment access 2
tansaclient/scripts/jawr_loader.jstansaclient/initGuiHTML_v1.js
-
LOWAlertStatementsShouldNotBeUsed 1
tansaclient/js/slick-grid/slick.grid.js
-
LOWpostinstall registry modification 1
tansaclient/js/draft-js/javascript-draft.js
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

559 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

Lingofy AS

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

38
Noisy-finding weight
x1.00
Publisher domain
styleguard.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
2
Portfolio

13 evidence rows available.

Finding Categories

9
Obfuscation
3
Network
559
IoC Indicators

YARA Rules Matched

18 rules(272 hits)
postinstall persistence mechanism credential env files LocalStorageShouldNotBeUsed DebuggerStatementsShouldNotBeUsed SQLInjection NoUseEval NoUseWeakRandom postinstall file download UntrustedContentShouldNotBeIncluded postinstall obfuscation postinstall system command postinstall crypto operations postinstall file manipulation postinstall network communication OriginsNotVerified postinstall environment access +2 more

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

The extension "StyleGuard Pro" presents a writing assistant that claims to provide "clear, concise and consistent text." The code structure reveals a tansaclient/ directory containing files like tansa.js, googleDocsAdapter.js, and lingofy/login.js, which align with Tansa's commercial proofreading and grammar checking products.

The findings breakdown tells a clear story. Of the 1085 total findings, 559 are classified as IoCs, 272 are code-smell, 9 are obfuscation, and 3 are network. Zero malware signatures matched anywhere in the extension.

The 559 IoC findings are almost entirely false positives from the extractor. The network endpoints list includes entries like 0-this.offset.relative.top-this.offset.parent.top, bounds.bottom-viewport.top, clientrect.top-eleboundingclientrect.top, and btn-group.open. These are JavaScript property access chains, arithmetic expressions, and CSS class names that the IoC extractor misidentified as domains. The only potentially real domain in the list is ajaxload.info, but without context on how it's used, it's insufficient to draw conclusions.

The 272 code-smell findings are low-severity matches that fire on any non-trivial JavaScript. Rules like postinstall_* match basic Node.js patterns, and credential_* matches any code referencing API keys. These are documented noise sources in the CVEQ platform.

The 9 obfuscation findings concentrate in tansaclient/ files. OBFUSCATION-unicode_heavy triggers in javascript-draft.js and googleDocsAdapter.js, which handle text processing for grammar checking and would naturally contain extensive Unicode handling. OBFUSCATION-dynamic_eval appears in about.js, gui.js, login.js, and tansa.js. While dynamic eval can be concerning, commercial software often uses these techniques for legitimate reasons like dynamic UI generation or configuration loading. Without malware signatures co-located with these obfuscation patterns, they don't indicate malicious intent.

The 3 network findings in js/serviceWorker.js show websocket and fetch calls at lines 1, 15, and 29. These are standard network operations for a writing assistant that needs to communicate with backend services for grammar checking.

The empty developer name and 0 user count are unusual but not conclusive. The extension declares no permissions or host permissions, which actually limits its attack surface. A grammar checker without host_permissions cannot read page content it wasn't explicitly given, reducing the risk of data exfiltration.

A skeptic might argue that the empty developer attribution combined with obfuscation in multiple files indicates a malicious actor hiding their identity. However, the absence of malware signatures, the presence of legitimate commercial code paths (tansaclient/), and the complete lack of suspicious domains in the IoC list undermine that interpretation. The findings are driven by known false positive patterns: IoC extractor garbage, code-smell noise, and obfuscation detection in commercial software.

Key Reasons

  • 559 IoCs are almost entirely JavaScript property access and CSS class names, not real domains
  • Zero malware signatures matched in the entire extension
  • Obfuscation findings are in tansaclient directory, suggesting legitimate commercial proofreading software
  • No permissions or host permissions declared, limiting attack surface
  • Network endpoints are generic fetch and websocket calls without suspicious destinations

False Positive Considerations

  • IoC extractor misidentified JavaScript property access chains and CSS class names as domains
  • Code-smell rules matched basic JavaScript patterns in non-trivial code
  • Obfuscation detector flagged legitimate commercial proofreading software code
  • High finding count inflated by bundled dependencies in tansaclient directory

Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 75%.

Edge version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
65
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
5.4.1.9
Apr 4, 2026
Risk range
65 to 65
Across analyzed versions
Latest analyzed version
5.4.1.10
Sep 29, 2026
Selected version
medium
Version
v5.4.1.10
2 days ago
Risk score
65
Findings
1085
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

Frequently Asked Questions