Is B.Point Saas Chrome Extension safe?

Clean risk

B.Point Saas Chrome Extension relays commands from WKI SaaS pages to a local native messaging host on Windows.

The extension injects a page-script API (bpsce-api.js) into specific Wolters Kluwer and B.Point SaaS domains that exposes a document.bpplugin.startWKITerm() function. When a page calls this function, the extension forwards the caller-supplied parameters verbatim—without sanitization—through a content script relay to its background service worker, which sends them to the it.wki.bpsaas native messaging host installed on the user's machine. All activity is scoped to four vendor-controlled domains: secure.bpointsaas.it, secure.nextstudiouil.it, bpsaas-to-prod.saaslab.wki, and dr-bpointsaas.wolterskluwer.it.

Wolters Kluwerv1.1.0.11Chrome Web Store
0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Updated 17 September 2026oblfbladhdphpmhkleohjnbfmefkeokd