StyleGuard Pro
The AI review rates the findings as likely false positive, but the risk score (65/100) still counts them.
Analysis record
- Analysed
- 2 days ago
- Version
- v5.4.1.10
- Artifact
- SHA256 AD4…D86
- Source
- Findings (non-IoC)
Is StyleGuard Pro safe?
StyleGuard Pro is a writing assistant that checks grammar and style. The extension's code includes a tansaclient/ directory with files like tansa.js and googleDocsAdapter.js, which are part of Tansa's commercial proofreading software. The extension declares no special permissions, meaning it cannot access your browsing history or read page content without explicit interaction.
The security scan found 1085 items, but nearly all are false alarms. The 559 "IoC" findings are mostly JavaScript code fragments like bounds.bottom-viewport.top and btn-group.open that the scanner misidentified as web addresses. The 272 "code-smell" findings are low-level matches that trigger on any complex JavaScript code. The 9 obfuscation findings appear in the Tansa client code, which handles Unicode text processing and dynamic interface generation. None of these findings include actual malware signatures.
The verdict follows because the scanner tripped on known false positive patterns. The IoC extractor flagged property access chains and CSS class names as domains. The code-smell rules matched basic JavaScript patterns. The obfuscation detector flagged legitimate commercial code. Without malware signatures or suspicious network destinations, these findings don't indicate malicious behavior. The extension's lack of permissions further limits what it can do, even if someone wanted to misuse it.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
18 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall persistence mechanism | 8 | tansaclient/styles/css/nimbus-sans-l/fonts/NimbusSanL-Reg.ttftansaclient/js/lib/purify.min.jstansaclient/js/lib/bootstrap-4.0.0/js/bootstrap.bundle.js +5 more | - |
| LOW | credential env files | 1 | tansaclient/js/draft-js/javascript-draft.js | - |
| LOW | LocalStorageShouldNotBeUsed | 6 | tansaclient/lingofy/login.htmltansaclient/scripts/gui.jstansaclient/tansaLoader.js +3 more | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 1 | tansaclient/js/draft-js/javascript-draft.js | - |
| LOW | SQLInjection | 11 | tansaclient/js/lib/bootstrap-4.0.0/js/bootstrap.bundle.min.jstansaclient/js/lib/bootstrap-4.0.0/js/bootstrap.jsjs/jquery/jquery-2.1.1.min.js +8 more | - |
| LOW | NoUseEval | 7 | tansaclient/scripts/lingofy/about.jstansaclient/scripts/lingofy/login.jstansaclient/js/slick-grid/slick.grid.js +4 more | - |
| LOW | NoUseWeakRandom | 20 | tansaclient/scripts/jquery.jsjs/jquery/jquery-2.1.1.min.jstansaclient/js/lib/bootstrap-4.0.0/js/bootstrap.bundle.js.map +17 more | - |
| LOW | postinstall file download | 14 | js/jquery/jquery.blockUI.jstansaclient/js/draft-js/javascript-draft.jstansaclient/scripts/about.js +11 more | - |
| LOW | UntrustedContentShouldNotBeIncluded | 3 | tansaclient/initGuiHTML_v1.jstansaclient/tansaLoader.jstansaclient/tansaDependencies.js | - |
| LOW | postinstall obfuscation | 32 | js/jquery/jquery-migrate-1.2.1.min.jstansaclient/styles/css/tansa/styles.csstansaclient/js/lib/bootstrap-4.0.0/js/bootstrap.bundle.js +29 more | - |
| LOW | postinstall system command | 46 | tansaclient/js/lib/bootstrap-4.0.0/js/bootstrap.js.maptansaclient/js/lib/bootstrap-4.0.0/css/bootstrap.csstansaclient/scripts/lingofy/login.js +43 more | - |
| LOW | postinstall crypto operations | 14 | tansaclient/scripts/gui.jstansaclient/js/lib/bootstrap-4.0.0/js/bootstrap.bundle.jstansaclient/scripts/jquery.js +11 more | - |
| LOW | postinstall file manipulation | 60 | tansaclient/initTansaLoader.jstansaclient/js/lib/bootstrap-4.0.0/js/bootstrap.bundle.jstansaclient/scripts/js/extenstions/client/tansa4ClientFigmaExtension.js +57 more | - |
| LOW | postinstall network communication | 40 | tansaclient/lingofy/login.htmltansaclient/styles/css/tansa/styles.cssmanifest.json +37 more | - |
| LOW | OriginsNotVerified | 5 | tansaclient/lingofy/licenseIssue.htmltansaclient/scripts/js/extenstions/client/tansa4ClientFigmaExtension.jstansaclient/about.html +2 more | - |
| LOW | postinstall environment access | 2 | tansaclient/scripts/jawr_loader.jstansaclient/initGuiHTML_v1.js | - |
| LOW | AlertStatementsShouldNotBeUsed | 1 | tansaclient/js/slick-grid/slick.grid.js | - |
| LOW | postinstall registry modification | 1 | tansaclient/js/draft-js/javascript-draft.js | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidenceLingofy AS
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
YARA Rules Matched
18 rules(272 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
The extension "StyleGuard Pro" presents a writing assistant that claims to provide "clear, concise and consistent text." The code structure reveals a tansaclient/ directory containing files like tansa.js, googleDocsAdapter.js, and lingofy/login.js, which align with Tansa's commercial proofreading and grammar checking products.
The findings breakdown tells a clear story. Of the 1085 total findings, 559 are classified as IoCs, 272 are code-smell, 9 are obfuscation, and 3 are network. Zero malware signatures matched anywhere in the extension.
The 559 IoC findings are almost entirely false positives from the extractor. The network endpoints list includes entries like 0-this.offset.relative.top-this.offset.parent.top, bounds.bottom-viewport.top, clientrect.top-eleboundingclientrect.top, and btn-group.open. These are JavaScript property access chains, arithmetic expressions, and CSS class names that the IoC extractor misidentified as domains. The only potentially real domain in the list is ajaxload.info, but without context on how it's used, it's insufficient to draw conclusions.
The 272 code-smell findings are low-severity matches that fire on any non-trivial JavaScript. Rules like postinstall_* match basic Node.js patterns, and credential_* matches any code referencing API keys. These are documented noise sources in the CVEQ platform.
The 9 obfuscation findings concentrate in tansaclient/ files. OBFUSCATION-unicode_heavy triggers in javascript-draft.js and googleDocsAdapter.js, which handle text processing for grammar checking and would naturally contain extensive Unicode handling. OBFUSCATION-dynamic_eval appears in about.js, gui.js, login.js, and tansa.js. While dynamic eval can be concerning, commercial software often uses these techniques for legitimate reasons like dynamic UI generation or configuration loading. Without malware signatures co-located with these obfuscation patterns, they don't indicate malicious intent.
The 3 network findings in js/serviceWorker.js show websocket and fetch calls at lines 1, 15, and 29. These are standard network operations for a writing assistant that needs to communicate with backend services for grammar checking.
The empty developer name and 0 user count are unusual but not conclusive. The extension declares no permissions or host permissions, which actually limits its attack surface. A grammar checker without host_permissions cannot read page content it wasn't explicitly given, reducing the risk of data exfiltration.
A skeptic might argue that the empty developer attribution combined with obfuscation in multiple files indicates a malicious actor hiding their identity. However, the absence of malware signatures, the presence of legitimate commercial code paths (tansaclient/), and the complete lack of suspicious domains in the IoC list undermine that interpretation. The findings are driven by known false positive patterns: IoC extractor garbage, code-smell noise, and obfuscation detection in commercial software.
Key Reasons
- 559 IoCs are almost entirely JavaScript property access and CSS class names, not real domains
- Zero malware signatures matched in the entire extension
- Obfuscation findings are in tansaclient directory, suggesting legitimate commercial proofreading software
- No permissions or host permissions declared, limiting attack surface
- Network endpoints are generic fetch and websocket calls without suspicious destinations
False Positive Considerations
- IoC extractor misidentified JavaScript property access chains and CSS class names as domains
- Code-smell rules matched basic JavaScript patterns in non-trivial code
- Obfuscation detector flagged legitimate commercial proofreading software code
- High finding count inflated by bundled dependencies in tansaclient directory
Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 75%.
Edge version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace