Is Omnidoc safe?

Clean risk

Omnidoc relays commands from omnidoc.fr pages to a local native host without a command allowlist.

The extension installs a content script on omnidoc.fr pages that listens for postMessage calls and forwards them to the background service worker. The background worker passes the full message payload directly to the native host fr.omnidoc.local_services, which handles local medical device operations such as reading a Vitale card. Because no command allowlist is applied before forwarding, any command accepted by the native host can be triggered by omnidoc.fr page content.

pierrev0.0.11Chrome Web Store
0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Data recipients

fr.omnidoc.local_services
Updated 17 September 2026bnfonipbkmojliindhiedahcfhlgiifm