Is NebulaCertURLMon safe?
NebulaCertURLMon forwards every HTTPS URL visited in the active tab to a locally-installed native application and can block navigation based on an allowlist it receives in return.
The extension connects to a native messaging host named 'vincerturlmonchcore' on startup and sends the URL of each HTTPS page load or tab switch to it via chrome.runtime.connectNative. The native host can respond with a base64-encoded list of URL patterns; when such a list is present, the extension blocks any navigation request whose URL does not match a pattern on the list and shows a desktop notification. This behavior is designed for enterprise URL monitoring and web filtering managed through the locally-installed VinCert/NebulaCert application.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 1.9.4. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
<all_urls>
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
Watch every request your browser makes
webRequest
Watch, block and rewrite every request your browser makes
webRequestBlocking
Act on the current tab, but only after you click the extension
activeTab
See the address and title of every tab you have open
tabs
Show you desktop notifications
notifications
Where it sends data
Destinations our analysis observed NebulaCertURLMon contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- vincerturlmonchcore (local native messaging host)
NebulaCertURLMon sends data to vincerturlmonchcore (local native messaging host). Named as a recipient in this extension's own analysis.