Is CTERA Edit safe?
CTERA Edit relays page-triggered CustomEvents to a native desktop application on all websites without origin validation.
The extension injects a content script on every http and https page that listens for CteraEditStart and CteraEditOpen CustomEvents. When those events fire, it forwards file path, username, and folder identifiers from the event payload directly to the native host com.ctera.ctera_edit via native messaging, without verifying that the triggering page is a CTERA portal. Any website can dispatch these events and influence which files the native application opens or edits.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 0.94. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
Where it sends data
Destinations our analysis observed CTERA Edit contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- com.ctera.ctera_edit
CTERA Edit sends data to com.ctera.ctera_edit. No other extension we have analysed sends data here.