Is Open in VLC Media Player™ safe?

Clean risk

Open in VLC Media Player™ uses a native messaging host to spawn a local application with the right-clicked URL as an argument.

When a user right-clicks a link or page, the extension sends a native message to a locally installed host ('net.freefinancetools.openfrombrowser') that includes the URL and a Node.js script instructing it to call child_process.spawn. The executable path defaults to VLC but is user-configurable via the options page. No user data is sent to remote servers; all activity stays between the browser and the local native host.

Free Appsv3.0.0Chrome Web Store
0Risk
Who publishes it

Free Apps - 3 other listings from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Free Apps

Same store account

3 other listings published from this account, 110k+ users between them, none of them carrying a finding.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 3.0.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Store data in your browser

    storage

  • Add items to the right-click menu

    contextMenus

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Updated 30 September 2026kbonopecbfhedlfpaphndlaoppmdppim