Is Integral CertHandler safe?

Low risk

Integral CertHandler relays unvalidated CustomEvent commands from any web page to a native certificate-handling app.

The extension's content script runs on every HTTP and HTTPS page and listens for a custom DOM event that any page script can dispatch. When such an event arrives, the content script forwards the full payload — including command, certificate, PIN, and key fields — to the background script without any caller validation. The background script then passes the data to the native host application via a native messaging port.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Integral Sistemasv1.1Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Updated 30 September 2026apaefgjnipgllidimohgphhcklbhblli