Is D.Bridge 2 safe?

Medium risk

D.Bridge 2 relays postMessage calls from any webpage to a local native messaging host with no origin allowlist.

The extension injects a content script on all URLs that listens for window.postMessage events and forwards them to the sk.ditec.dbridge2.nm native host via a background service worker. Any JavaScript running on any page can initiate or send requests to the native host without restriction, as the only guard filters cross-frame sources but not arbitrary same-page scripts. The native host is part of DITEC's qualified electronic signature suite for Slovak government services.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

DITEC, a. s.v2.0.6.0Chrome Web Store
40Risk
Who publishes it

DITEC, a.s. - no other listings under this identity, 1 shared hostname

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
DITEC, a. s.
Declared legal entity
DITEC, a.s.
Registered address
Mlynské Nivy 19474/55, Bratislava-Ružinov 82109, SK
Registered contact
Ing. Csaba Baráth

Shared hosts - 1 hostname

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

ditec.sk
Also called by 2 other listings, including D.Bridge 2

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Updated 30 September 2026fngbdhimbgbonhlibfmiemipheabfdmj