Is CreaSign safe?

Low risk

CreaSign bridges any webpage's postMessage calls to the locally installed CreaSign native app without validating the message origin.

The extension injects a content script on all pages that listens for postMessage events and forwards their payloads to the native CreaSign digital-signature application via native messaging. Because the content script only checks that the message came from the same window object (not the page's origin), any script on any loaded page can send arbitrary data to the native host com.crea.creasign. No network data transmission occurs; communication is limited to the user's own machine.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

CREA d.o.o.v3.0Chrome Web Store
20Risk
Who publishes it

CREA d.o.o. - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
CREA d.o.o.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 3.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Updated 30 September 2026ngdilonafabhaefomphllifjknaeabne