Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeAntidote Connector
Findings · 3
MEDIUM FINDINGS · 3
  1. 01On any HTTP/HTTPS page (content_scripts matches http://*/* and https://*/*), the extension's antidote.js exposes a window.postMessage handler that, when activated by the page setting <html antidoteapi_jsconnect="true"> and dispatching annoncePresence, returns the local Antidote desktop app's WebSocket port (portWS) to the page with no origin validation
  2. 02Same JSConnect window.postMessage handler accepts lanceOutilConnect from any opted-in page with no origin validation, allowing arbitrary sites to programmatically launch Antidote tools (Correcteur/Dictionnaires/Guides) against page-controlled DOM elements
  3. 03On every page navigation in <all_urls>, the content script reports the page favicon (as a data: URL) and full window.location.href back to the background script over the runtime port
OTHER EXTENSIONS

Is Antidote Connector safe?

Medium risk

No summary available.

Druide informatiquev12.4.0Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026com.druide.antidote-safari.connecteur

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact