Is Docusign PKI safe?
DocuSign PKI writes the extension's runtime ID into the DOM on DocuSign signing pages, where other scripts on that page can read it.
The extension bridges DocuSign signing pages to a locally installed DocuSign PKI native app using Chrome's native messaging API. Content scripts run only on DocuSign signing pages (*.docusign.com, .net, .mil). As part of its handshake mechanism, the extension inserts a hidden div containing its Chrome runtime ID, which any other JavaScript on the same DocuSign page — including third-party analytics or scripts injected by an XSS — can read to confirm the extension is installed.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itDocusign - no other listings under this identity
Docusign - no other listings under this identity
What this publisher told the store about itself, and the other listings that told it the same thing.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 25.1.00.00. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
Where it sends data
Destinations our analysis observed DocuSign PKI contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- com.docusign.chrome.sign
DocuSign PKI sends data to com.docusign.chrome.sign. No other extension we have analysed sends data here.