Is ESMART Token Web Plugin safe?

High risk

ESMART Token Web Plugin exposes a PKCS#11 hardware-token API to any webpage via an unauthenticated postMessage bridge injected on all sites.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

isbcholdingv3.0.19Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Updated 22 July 2026cblhedkfmbhcikepclfiehohcpfpbmnb