Is D.Bridge 2 safe?
D.Bridge 2 relays postMessage calls from any webpage to a local native messaging host with no origin allowlist.
The extension injects a content script on all URLs that listens for window.postMessage events and forwards them to the sk.ditec.dbridge2.nm native host via a background service worker. Any JavaScript running on any page can initiate or send requests to the native host without restriction, as the only guard filters cross-frame sources but not arbitrary same-page scripts. The native host is part of DITEC's qualified electronic signature suite for Slovak government services.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itDITEC, a.s. - no other listings under this identity, 1 shared hostname
DITEC, a.s. - no other listings under this identity, 1 shared hostname
What this publisher told the store about itself, and the other listings that told it the same thing.
Shared hosts - 1 hostname
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.