Chrome Web Store
8Versions
1Code reviewed

No malware found

In code review (v0.0.0.23)

Our reviewer read version 0.0.0.23 — the most recent version we have reviewed — and found no malicious behaviour. The version shown here has not been individually reviewed yet.

What our analysis found

TrendAI™ Toolbar for Enterprise, used by 7,000,000 people, showed no malicious code in Extension Auditor's review. Its permissions mean it can inject scripts into pages. It was last updated in June 2026.

The extension is a legitimate Trend Micro enterprise security tool performing DLP and web reputation blocking via native messaging. All data collection (email, URLs, file hashes, email content) is sent locally to the native app for corporate policy enforcement, with no unauthorized exfiltration to third parties. Broad permissions are essential for its core functionality. The ML score (0.00) and permhash cluster (0% malware) corroborate benign intent.

TrendAI™ Toolbar for Enterprise

TrendAI™ Toolbar for Enterprise

ID: iiipkionnkhdcficbbpionjlfmnjgnlg

Supported Languages

🇹🇼Chinese (Traditional)
🇨🇿Czech
🇺🇸English
🇫🇷French
🇩🇪German
🇬🇷Greek
🇭🇺Hungarian
🇮🇹Italian
🇯🇵Japanese
🇰🇷Korean
🇵🇱Polish
🇷🇴Romanian
🇷🇺Russian
🇪🇸Spanish

Extension Info & Metadata

Status
Active
Version
0.0.0.24
Size
0.06 MB
Rating
1.3/5
Reviews
42
Users
7,000,000
Type
Extension
Updated
Jun 10, 2026
Category
Developer tools
Price
Free
Featured
No
Visibility
Unlisted
Mature
No
By Google
No
Trusted
No
This publisherTrack record
1extension
All still listed
Scanned by Extension Auditor — Low RiskDevelopers: embed this badge to link to this report.

Publisher Contextual Analysis

Author
macdeveloperView Profile
Country
US
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Address
225 East John Carpenter Freeway, Suite 1500 Irving, TX 75062 US
Website
Visit
Extensions
1
Active
1
Obsolete
0
Listed
0
Unlisted
1
Users
7,000,000

Screenshots & videos

Screenshot 1

Install growth

Item
Type
Severity
Description
scripting
Permission
Critical
This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to.
http://*/*
Host
Critical
Broad host access — the extension can read/modify content on every website.
https://*/*
Host
Critical
Broad host access — the extension can read/modify content on every website.
nativeMessaging
Permission
High
This permission enables communication with applications installed on your computer. Rated High because it can exchange data with native programs, potentially exposing system-level information and local files.
downloads
Permission
High
This permission controls file downloads and accesses download history. Rated High because it can download malicious files, access sensitive downloaded documents, and track user download patterns.
identity
Permission
High
This permission accesses Chrome identity service and user information. Rated High because it can obtain OAuth tokens, access connected accounts, and impersonate the user in authenticated service.
identity.email
Permission
High
This permission directly accesses the user's email address. Rated High because it reveals personally identifiable information and can be used for tracking or targeting.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 10% increase: Early script execution enables pre-emptive content manipulation
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
activeTab
Permission
Medium
This permission grants temporary access to the current tab. Rated Medium because it can access current page content when invoked, though limited to user-initiated actions.
Early Content Script Execution
Risk Factor
Medium
This extension runs content scripts at document_start.
alarms
Permission
Low
This permission schedules periodic tasks. Rated Low because it can only trigger events at specified times without access to sensitive data.

Gain full insight into all external connections.

Upgrade for full visibility.

About this extension

Enhance web browser security with TrendAI™ security software.

Read the publisher’s full description

The extension is for Trend Micro Cloud One enterprise product to do the https rating and block malicious website. Enterprise user who installed Trend Micro Cloud One will have this extension installed to have https protection in chrome.

User reviews

Extension files

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.

URLs
2

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

No URLs found
No IP addresses found

Gain full insight into all external connections.

Upgrade for full visibility.

Showing 1 to 8 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files detected

No comparable text files found between these versions.

Gain full insight into all external connections.

Upgrade for full visibility.

Popular in Developer Tools