Is CreaSign safe?
CreaSign bridges any webpage's postMessage calls to the locally installed CreaSign native app without validating the message origin.
The extension injects a content script on all pages that listens for postMessage events and forwards their payloads to the native CreaSign digital-signature application via native messaging. Because the content script only checks that the message came from the same window object (not the page's origin), any script on any loaded page can send arbitrary data to the native host com.crea.creasign. No network data transmission occurs; communication is limited to the user's own machine.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itCREA d.o.o. - no other listings under this identity
CREA d.o.o. - no other listings under this identity
What this publisher told the store about itself, and the other listings that told it the same thing.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 3.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging