Is Docutracks Signer safe?
Docutracks Signer exposes a native signing bridge on all pages, letting any page script trigger a signing operation via a CustomEvent.
The extension injects a content script into all pages that listens for a 'signFileHash' CustomEvent. When any page dispatches this event with a hash value, the content script forwards the request through the extension's background worker to a native messaging host ('com.dataverse.docutrackssigner'), which performs the signing operation and returns the result. The extension also appends a detectable DOM element to every page, revealing its presence to any site the user visits.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itDataverse LTD - 1 other listing from the same operator, 1 of them carrying a finding
Dataverse LTD - 1 other listing from the same operator, 1 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
1 other listing published from this account, 1k+ users between them. 1 of them carries a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 3.0.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
<all_urls>
Act on the current tab, but only after you click the extension
activeTab
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging