Is Foxit PDF Creator safe?
Foxit PDF Creator reads session cookies for the current tab and passes them to the locally-installed Foxit native host during PDF conversion.
When a user triggers a PDF conversion via the right-click context menu, the extension reads all cookies for the active tab URL using the cookies permission and includes them alongside the page URL, title, and HTML content in a message sent to the Foxit native application (com.foxit.chromeaddin) installed on the same machine. This data transfer stays local — no remote server receives the cookies. The behavior is scoped to user-initiated actions only.
Who publishes itFoxit Software - 1 other listing from the same operator, none carrying a finding
Foxit Software - 1 other listing from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
1 other listing published from this account, 10k+ users between them, none of them carrying a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 12.1.0.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 2026.2.0.0, which we have not unpacked yet.
Add items to the right-click menu
contextMenus
See the address and title of every tab you have open
tabs
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
Read and change cookies, including the ones that keep you signed in
cookies
Where it sends data
Destinations our analysis observed Foxit PDF Creator contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- com.foxit.chromeaddin (local native host)
Foxit PDF Creator sends data to com.foxit.chromeaddin (local native host). Named as a recipient in this extension's own analysis.