Is Assinador Digital Qcertifica safe?

Medium risk

Assinador Digital Qcertifica relays postMessage requests from any web page to a native signing host without validating the message origin.

The extension's content script runs on all websites and arms a postMessage listener whenever a page contains a specific HTML element. Any page-context script can trigger this bridge by including that element and sending a message of the expected type, which the extension forwards verbatim to the native host br.com.quicksoft.signer.nativehost. There is no origin allow-list or user confirmation before native host operations are dispatched.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

quicksoft.sistemasv0.5.0Chrome Web Store
45Risk
Who publishes it

quicksoft.sistemas - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
quicksoft.sistemas

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 0.5.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Where it sends data

Destinations our analysis observed Qcertifica contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • br.com.quicksoft.signer.nativehost

    Qcertifica sends data to br.com.quicksoft.signer.nativehost. No other extension we have analysed sends data here.

Updated 30 September 2026jlihldkpooaidnkjckkkehahkbhbmign