Is Open in Foxit™ Reader safe?

Medium risk

Open in Foxit™ Reader passes web-origin PDF URLs to a native shell command without sanitization when a custom Foxit path is configured.

The extension intercepts PDF link clicks across all websites and sends the URL to a native messaging host (com.add0n.node), which constructs and runs a shell command via child_process.exec. When users have configured a custom Foxit executable path, the raw web-origin URL is concatenated directly into the shell command string with no escaping. The extension also fetches its native client installer from the GitHub Releases API without verifying any checksum or code signature before offering it for installation.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

lunu.bounirv0.2.4Chrome Web Store
45Risk
Who publishes it

lunu.bounir - 3 other listings from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Same store account

3 other listings published from this account, 480k+ users between them, none of them carrying a finding.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 0.2.4. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Store data in your browser

    storage

  • Add items to the right-click menu

    contextMenus

  • Show you desktop notifications

    notifications

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

  • Start, monitor and manage your downloads

    downloads

  • Act on the current tab, but only after you click the extension

    activeTab

Where it sends data

Destinations our analysis observed Open in Foxit™ Reader contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • api.github.com

    Open in Foxit™ Reader sends data to api.github.com. 11 other extensions we have analysed send data here.

Updated 30 September 2026lhplfipknbnglagbgbfogdaihdcekfga