Is OmniDefend SSO Extension safe?

Low risk

OmniDefend SSO Extension accepts forged postMessage tokens without origin validation, allowing any web page to read the Windows username when Windows autologin is configured.

The extension installs a message listener on every HTTP and HTTPS page that gates on a data-field token rather than the message origin. Any page can forge that token and send a request that causes the extension to query a native host for the current Windows username, which is then broadcast back via window.postMessage to all listeners on the page. The exposure occurs only when the Windows autologin feature is active in OmniDefend's server settings.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Softex Incorporatedv3.0.5.26260Chrome Web Store
20Risk
Who publishes it

Softex - 1 other listing from the same operator, 1 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Softex Incorporated
Declared legal entity
Softex
Registered address
9300 Jollyville Rd #201, Austin, TX 78759-7455, US
Registered contact
Apurva Bhansali

Same store account

1 other listing published from this account, 6k+ users between them. 1 of them carries a finding.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Updated 30 September 2026deeppkmgnnimofmekmncjmncpcbodmbl