Is Integral CertHandler safe?
Integral CertHandler relays unvalidated CustomEvent commands from any web page to a native certificate-handling app.
The extension's content script runs on every HTTP and HTTPS page and listens for a custom DOM event that any page script can dispatch. When such an event arrives, the content script forwards the full payload — including command, certificate, PIN, and key fields — to the background script without any caller validation. The background script then passes the data to the native host application via a native messaging port.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.