Is Dragon Web Extension safe?

Low risk

Dragon Web Extension accepts cross-origin messages on all pages, allowing any window to trigger synthetic clicks on page elements.

The extension injects a messaging layer into every page that listens for postMessage events without validating the sender's origin. Any cross-origin window or iframe can send a specially crafted message to invoke clicks on links, buttons, and form elements that the extension has indexed. This is possible because the extension's runtime ID — used as a message prefix — is exposed via a web-accessible resource readable by any page script.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Nuance Communications, Inc.v15.7.100.1674Chrome Web Store
20Risk
Who publishes it

NUANCE COMMUNICATIONS, INC. - 3 other listings from the same operator, 1 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Nuance Communications, Inc.
Declared legal entity
NUANCE COMMUNICATIONS, INC.
Registered address
1 Wayside Rd, Burlington, MA 01803-4609, US
Registered contact
NUANCE COMMUNICATIONS, INC.

Same store account

2 other listings published from this account, 1.0M+ users between them, none of them carrying a finding.

Same operator - 1 listing

Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 15.7.100.1674. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    *://*/*

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Updated 30 September 2026ddaloccgjfibfpkalenodgehlhkgoahe