Firefox Add-ons Verified

BugKit Visual Bug Reporting

by Dracon
ffbac721-780f-5625-adf1-8074074836c4 | v1.2.1
61/ 100
MEDIUM risk
-3 since v1.1.0
Risk verdict
Review before use

Score-based assessment (medium risk, 61/100). Last analyst review covers version 1.1.0.

Analysis record

Analysed
4 weeks ago
Version
v1.2.1
Artifact
SHA256 979…752
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

70 detail rows

YARA Rule Matches

13 rules
SeverityRuleHitsFilesMetadata
LOWcredential env files 3
chunks/options-BUHiIuCZ.jsbackground.jscontent-scripts/content.js
-
LOWpostinstall persistence mechanism 2
background.jscontent-scripts/content.js
-
LOWpostinstall file download 8
rrweb.jschunks/options-BUHiIuCZ.jspage-instrumentation.js +5 more
-
LOWNoUseWeakRandom 4
page-instrumentation.jschunks/index-BHgQiXBV.jsbackground.js +1 more
-
LOWpostinstall obfuscation 6
content-scripts/content.jsrrweb.jschunks/options-BUHiIuCZ.js +3 more
-
LOWpostinstall crypto operations 4
chunks/options-BUHiIuCZ.jsbackground.jschunks/index-BHgQiXBV.js +1 more
-
LOWpostinstall file manipulation 9
chunks/offscreen-NiXevi8N.jsassets/options-JevPvTQw.cssrrweb.js +6 more
-
LOWpostinstall system command 11
_locales/en/messages.jsonindex.htmlassets/options-JevPvTQw.css +8 more
-
LOWpostinstall environment access 3
chunks/index-BHgQiXBV.jschunks/popup-DX85XD3G.jschunks/options-BUHiIuCZ.js
-
LOWAlertStatementsShouldNotBeUsed 1
background.js
-
LOWpostinstall network communication 8
chunks/offscreen-NiXevi8N.jsrrweb.jschunks/options-BUHiIuCZ.js +5 more
-
LOWDebuggerStatementsShouldNotBeUsed 1
manifest.json
-
LOWcredential metamask extension 1
chunks/options-BUHiIuCZ.js
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

39 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

Dracon

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

43
Noisy-finding weight
x1.00
Publisher domain
dracon.uk
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
17
Portfolio

12 evidence rows available.

Finding Categories

8
Network
39
IoC Indicators

YARA Rules Matched

13 rules(61 hits)
credential env files postinstall persistence mechanism postinstall file download NoUseWeakRandom postinstall obfuscation postinstall crypto operations postinstall file manipulation postinstall system command postinstall environment access AlertStatementsShouldNotBeUsed postinstall network communication DebuggerStatementsShouldNotBeUsed credential metamask extension

Requested Permissions

9 permissions
debugger

Full access to Chrome DevTools debugging protocol

Dangerous
<all_urls>

Access and modify data on every website you visit

Dangerous
cookies

Read and modify cookies on all sites

High
tabs
Medium
storage
Low
scripting
Low
https://dracon.uk/*
Low
https://*.dracon.uk/*
Low
https://api.github.com/*
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

The BugKit Visual Bug Reporting extension has a high number of IoC findings, but upon closer inspection, these findings appear to be related to the extension's functionality of auto-capturing screen, console logs, and network requests for faster debugging. The IoC findings are primarily related to XIOC detected domains, such as remoteid.map, doctype.name, and d.documentelement.style, which do not seem to be malicious. The extension's description and functionality suggest that it is a legitimate tool for bug reporting and debugging. However, the lack of developer information and the high number of IoC findings may raise some concerns. A counterargument to this verdict could be that the extension's ability to capture network requests and console logs could potentially be used for malicious purposes, such as data exfiltration. However, there is no evidence to suggest that this is the case, and the extension's functionality appears to be focused on legitimate debugging and bug reporting purposes. Therefore, based on the evidence, it is likely that this extension is a false positive.

Key Reasons

  • High number of IoC findings related to XIOC detected domains
  • Lack of developer information
  • Extension's functionality appears to be focused on legitimate debugging and bug reporting purposes

False Positive Considerations

  • IoC extractor garbage
  • XIOC detected domains

Reviewed 2026-05-31; recommended action: suppress false positive; model confidence 80%.

Firefox version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
61
Change since first
-3
Change from previous
-3
Versions:
First analyzed version
1.1.0
May 30, 2026
Risk range
61 to 64
Across analyzed versions
Latest analyzed version
1.2.1
Sep 3, 2026
Selected version
medium
Version
v1.2.1
4 weeks ago
Risk score
61
Findings
109
Change vs previous
-3

Pick any point on the chart to explore that version's code below.

About This Extension

BugKit is a privacy-first bug reporting tool that works like a dashcam for web development. <strong>What it captures:</strong> - Screenshots and screen recordings (Chrome only; Firefox gets screenshots only) - Console logs and JavaScript errors - Network requests and API responses - User interactions (clicks, inputs, navigation) <strong>Key features:</strong> - Automatic capture with rage-click detection (5 rapid clicks triggers auto-bug report) - Smart redaction that removes tokens, cookies, and PII before bundling - One-click ZIP export with an interactive replay viewer - Works on both Chrome and Firefox <strong>Privacy:</strong> All processing happens locally. No data leaves your browser unless you explicitly export and share a bug report bundle. <em>Note: Video recording feature requires Chrome APIs and is automatically disabled on Firefox.</em>

Frequently Asked Questions