Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeDokobit e-signing and e-identification
Findings · 3
LOW FINDINGS · 3
  1. 01isign-script.js injected on all pages exposes IsignChromeSigning constructor globally, enabling extension fingerprinting
  2. 02Native messaging relay sends PKI signing data (certificate hex, document hash) to local lt.isign.chromesigning app on ~100 allowlisted partner domains
  3. 03Content script on *://*/* injects isign-script.js (WAR accessible from https://*/*) into every page, enabling extension fingerprinting by any HTTPS web page
OTHER EXTENSIONS

Is Dokobit e-signing and e-identification safe?

Low risk

No summary available.

Dokobitv1.1.69Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026cmcgkhihcjkdlgiackjkpcjpbgbpdmgb

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact