Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeNextsense XML Signing Component
Findings · 3
+1 more finding locked
HIGH FINDINGS · 3
  1. 01externally_connectable.ids=['*'] lets any installed Chrome extension invoke PKI signing and certificate enumeration via native messaging host nextsense.signing.component
  2. 02externally_connectable.ids=['*'] allows any installed Chrome extension to invoke XML signing operations (GetCertificates, SignXml, SignHash) without sender validation
  3. 03Content script injected on all HTTP/HTTPS pages exposes XmlSignExtension global, enabling extension fingerprinting by any web page
+1 more finding locked
OTHER EXTENSIONS

Is Nextsense XML Signing Component safe?

High risk

No summary available.

https://www.nextsense.comv1.0.7.7Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+1 more finding not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026ccdgonnidaghcdicoebncgncfmpagpdk

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact