Is Assinador Digital Qcertifica safe?
Assinador Digital Qcertifica relays postMessage requests from any web page to a native signing host without validating the message origin.
The extension's content script runs on all websites and arms a postMessage listener whenever a page contains a specific HTML element. Any page-context script can trigger this bridge by including that element and sending a message of the expected type, which the extension forwards verbatim to the native host br.com.quicksoft.signer.nativehost. There is no origin allow-list or user confirmation before native host operations are dispatched.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itquicksoft.sistemas - no other listings under this identity
quicksoft.sistemas - no other listings under this identity
What this publisher told the store about itself, and the other listings that told it the same thing.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 0.5.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
Where it sends data
Destinations our analysis observed Qcertifica contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- br.com.quicksoft.signer.nativehost
Qcertifica sends data to br.com.quicksoft.signer.nativehost. No other extension we have analysed sends data here.