Is INISAFE SmartManagerEX safe?
High risk
Native messaging bridge extension with broad host permissions (*://*/*) that enables arbitrary native code execution through a privileged messaging interface. Contains dynamic callback execution vulnerability where callback names from native host are invoked via window[callback](), creating potential for code execution if the native host is compromised.
75Risk
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.