Adobe Photoshop
The AI review rates the findings as likely false positive, but the risk score (53/100) still counts them.
Analysis record
- Analysed
- 1 weeks ago
- Version
- v1.0.24
- Artifact
- SHA256 0C6…F95
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
LowPublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
Requested Permissions
6 permissionsAccess and modify data on every website you visit
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
This extension is published by Adobe using the verified email address [email protected], which is a strong indicator of legitimacy. The extension description states it provides background removal and color adjustment features with access to Photoshop web, consistent with Adobe's product line.
The security scan identified 11 findings, all classified as medium severity. There are zero malware signatures, zero obfuscation detections, and zero suspicious domain IoCs in the entire extension. This absence of actual malicious indicators is the most important signal.
The single manifest finding (MANIFEST-SENSITIVE-PERM-TABS in manifest.json) flags the tabs permission as potentially sensitive. However, this permission is legitimate for an extension that modifies web pages and integrates with Photoshop web functionality. The permission matches the extension's stated purpose.
All 10 network findings are generic fetch and socket_io calls located in bundled chunk files: chunks/storage-xiDPc5Q0.js, background.js, chunks/editor-B8Unbvnx.js, chunks/newrelic-CY7kDpVp.js, and chunks/aggregate-base-C1YnNr2T.js. These are webpack bundle outputs, which is standard for modern JavaScript applications. The network calls represent normal communication with Adobe's services for the extension's functionality. Notably, none of these findings reference suspicious domains like query., search., or unknown third-party servers.
The file naming convention (chunks/* with hash identifiers) confirms this is a properly bundled application. The presence of newrelic-CY7kDpVp.js indicates New Relic monitoring, a legitimate enterprise analytics service commonly used by large companies like Adobe.
A skeptic might argue that 700,000 users and network activity could mask malicious behavior. However, the evidence contradicts this: zero malware signatures, zero obfuscation, zero suspicious domains, and a verified Adobe publisher email. If this were malicious, we would expect at least one of these critical indicators. The network findings are generic patterns that fire on any extension making HTTP requests, which is necessary for a cloud-connected Photoshop tool.
This extension demonstrates the expected behavior of a legitimate Adobe product: proper bundling, verified publisher identity, and network calls consistent with its described functionality. The findings are false positives driven by the scanner's inability to distinguish legitimate network activity from malicious exfiltration in bundled code.
Key Reasons
- Verified Adobe publisher ([email protected])
- Zero malware signatures detected
- Zero obfuscation findings
- Zero suspicious domain IoCs
- Network activity consistent with described functionality
False Positive Considerations
- Bundled webpack chunks triggering network findings
- Generic fetch/socket_io patterns in legitimate code
- Enterprise analytics library (New Relic) in bundle
Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 95%.
Chrome version history
Risk trend by version
3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Adobe Acrobat: PDF edit, convert, sign tools
[email protected]
Adobe Experience Platform Debugger
[email protected]
Adobe Experience Cloud Visual Editing Helper
[email protected]
Adobe Workfront review tool
[email protected]
AEM Sidekick
[email protected]
Activity Map v4
[email protected]