Is CAD Viewer safe?
CAD Viewer accepts an auth token from any page on localhost, not just its own login page, and stores it as the user's session.
CAD Viewer injects a script into any page served from localhost (any port) as well as its own cadviewer.co site, listening for a postMessage carrying a user identity and session token. It does not check where that message actually came from beyond it being the same window, so any local process that can open an HTTP server on the machine can send a forged token, which the extension saves to storage and forwards into its Google Drive/Gmail content script and its side-panel viewer iframe.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itRhovium - no other listings under this identity
Rhovium - no other listings under this identity
What this publisher told the store about itself, and the other listings that told it the same thing.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 0.0.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on drive.google.com
*://drive.google.com/*
Read and change your data on mail.google.com
*://mail.google.com/*
Read and change your data on cadviewer.co
*://*.cadviewer.co/*
Show a panel beside the page
sidePanel
Store data in your browser
storage
Add items to the right-click menu
contextMenus
See the address and title of every tab you have open
tabs
Where it sends data
Destinations our analysis observed CAD Viewer contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- cadviewer.co
CAD Viewer sends data to cadviewer.co. No other extension we have analysed sends data here.