Is CFCA CertEnrollment.zjmtbank Extension safe?

Low risk

The extension bridges scoped bank and CA web pages to native messaging hosts, but accepts the host name from the caller without validation.

CFCA CertEnrollment.zjmtbank Extension acts as a native messaging relay for pages on mintaibank.com, zjmtbank.com, and cfca.com.cn. When a page requests a connection, it supplies the native host name directly; the extension passes that name to chrome.runtime.connectNative without checking it against any allowlist. A page on any permitted origin can therefore request a connection to any native messaging host registered on the user's machine and send arbitrary payloads through it.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

浙江民泰商业银行v3.2.0.3Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 3.2.0.3. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on mintaibank.com

    https://*.mintaibank.com/*

  • Read and change your data on zjmtbank.com

    https://*.zjmtbank.com/*

  • Read and change your data on cfca.com.cn

    http://*.cfca.com.cn/* and 1 more

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Updated 30 September 2026ekjkdponophncgphllhplkelgpogjgjd