Is Jazz-MIDI safe?

Low risk

Jazz-MIDI exposes a native MIDI host to any website via a CustomEvent bridge with no origin filtering.

The extension injects a content script on all URLs that listens for 'jazz-midi' CustomEvents fired by page scripts. Any website can trigger the event to open a bidirectional channel to the native host 'com.jazz_soft.jazz_midi', sending arbitrary MIDI commands and reading responses written back to the DOM. No allowlist restricts which sites can invoke this bridge.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Jazz-Softv1.0.2.0Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 1.0.2.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Updated 21 September 2026jhdoobfdaejmldnpihidjemjcbpfmbkm