Is CFCA CryptoKit.Paperless.broaderway Extension safe?

Low risk

The extension lets any page on broaderway.com.cn tell it which native messaging host to connect to, instead of enforcing one fixed host.

This CFCA smart-card tool relays transaction-signing requests between broaderway.com.cn web pages and a local native messaging host. The onMessageExternal handler takes the native host name and payload straight from the calling page's request and passes them to chrome.runtime.connectNative/sendNativeMessage, with no allowlist of permitted host names beyond Chrome's externally_connectable page-origin restriction. Native host replies are piped straight back to the calling page.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

fengminxdv3.4.0.2Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Updated 20 September 2026eekakoanllcfleakpccnlfkijcppenbg