Is CFCA CryptoKit.Paperless.broaderway Extension safe?
The extension lets any page on broaderway.com.cn tell it which native messaging host to connect to, instead of enforcing one fixed host.
This CFCA smart-card tool relays transaction-signing requests between broaderway.com.cn web pages and a local native messaging host. The onMessageExternal handler takes the native host name and payload straight from the calling page's request and passes them to chrome.runtime.connectNative/sendNativeMessage, with no allowlist of permitted host names beyond Chrome's externally_connectable page-origin restriction. Native host replies are piped straight back to the calling page.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.