Is B.Point Saas Chrome Extension safe?
B.Point Saas Chrome Extension relays commands from WKI SaaS pages to a local native messaging host on Windows.
The extension injects a page-script API (bpsce-api.js) into specific Wolters Kluwer and B.Point SaaS domains that exposes a document.bpplugin.startWKITerm() function. When a page calls this function, the extension forwards the caller-supplied parameters verbatim—without sanitization—through a content script relay to its background service worker, which sends them to the it.wki.bpsaas native messaging host installed on the user's machine. All activity is scoped to four vendor-controlled domains: secure.bpointsaas.it, secure.nextstudiouil.it, bpsaas-to-prod.saaslab.wki, and dr-bpointsaas.wolterskluwer.it.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.