Is CIVR Connector safe?

Low risk

CIVR Connector accepts postMessage from any web page and uses it to auto-fill and submit DICOM viewer login credentials.

On PACS radiology pages, CIVR Connector listens for postMessage events without checking the sender's origin, so any page that can open one of these sites in a new window can send it a username and password to store. When the user next navigates to the DICOM viewer login page, the extension automatically fills in and submits whatever credentials it was sent, without confirming they came from the user's own device.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

ci-chromedevv1.0.1.1Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Updated 20 September 2026knobijobhdilffnhdfphgmnbkkkihjgg