Is ESMART Token Web Plugin safe?

Low risk

ESMART Token Web Plugin exposes a PKCS#11 hardware-token API to any webpage via an unauthenticated postMessage bridge injected on all sites.

The extension injects a content script on every page that forwards postMessage events — validated only by a hardcoded string present in the public bundle — to a local ESMART PKI Client HTTP server. Any page can invoke commands including certificate enumeration, PIN-based login, and digital signing of arbitrary data. Certificate metadata such as subject email, serial number, and PEM-encoded certificates can be read from a connected token without prior device authentication.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

isbcholdingv3.0.19Chrome Web Store
20Risk
Who publishes it

isbcholding - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
isbcholding

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 3.0.19. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    *://*/*

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

  • See the address and title of every tab you have open

    tabs

  • Read and change cookies, including the ones that keep you signed in

    cookies

  • Store data in your browser

    storage

Where it sends data

Destinations our analysis observed ESMART Token Web Plugin contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • localhost (ESMART PKI Client HTTP server)

    ESMART Token Web Plugin sends data to localhost (ESMART PKI Client HTTP server). Named as a recipient in this extension's own analysis.

Updated 30 September 2026cblhedkfmbhcikepclfiehohcpfpbmnb