Is ESEP Crypto safe?
Clean risk
ESEP Crypto relays page-supplied data from content scripts to local native messaging hosts without input validation.
The extension listens for a custom DOM event ('EsepCryptoExtensionQuery') fired by the active page, parses the event payload as JSON, and forwards it to one of two local native messaging hosts (com.topcase.cryptohost or com.topcase.cryptoupdaterhost). Responses from the native host are relayed back to the page. No external servers receive this data; communication is between the browser extension and a locally installed application.
0Risk
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.