Is CTERA Edit safe?

Low risk

CTERA Edit relays page-triggered CustomEvents to a native desktop application on all websites without origin validation.

The extension injects a content script on every http and https page that listens for CteraEditStart and CteraEditOpen CustomEvents. When those events fire, it forwards file path, username, and folder identifiers from the event payload directly to the native host com.ctera.ctera_edit via native messaging, without verifying that the triggering page is a CTERA portal. Any website can dispatch these events and influence which files the native application opens or edits.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

CTERA Networks Ltdv0.94Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 0.94. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Where it sends data

Destinations our analysis observed CTERA Edit contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • com.ctera.ctera_edit

    CTERA Edit sends data to com.ctera.ctera_edit. No other extension we have analysed sends data here.

Updated 21 September 2026clcanilindnkpmffpdadmihenpagcpin