Is ActivID CMS extension safe?
ActivID CMS extension exposes a native messaging bridge to any HTTPS page that dispatches a custom DOM event.
The extension injects a content script on all HTTPS sites that listens for a custom DOM event named load-hid-extension. When any page fires that event and provides hidden DOM inputs, the content script connects to the native host com.hidglobal.cms.portal.client and relays base64-encoded messages between the page and the host application. Because the content script is not restricted to HID-affiliated origins, any HTTPS site can initiate this native messaging channel.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itHID Global - 1 other listing from the same operator, none carrying a finding
HID Global - 1 other listing from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
1 other listing published from this account, 2.0M+ users between them, none of them carrying a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 5.13.0.78. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Act on the current tab, but only after you click the extension
activeTab
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
Where it sends data
Destinations our analysis observed ActivID CMS contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- com.hidglobal.cms.portal.client
ActivID CMS sends data to com.hidglobal.cms.portal.client. No other extension we have analysed sends data here.