Is PDF-XChange safe?

Medium risk

PDF-XChange relays unvalidated postMessage URLs from any page script to a native host application on the user's computer.

The extension injects a content script into every page and listens for postMessage events. When a message with type PDFXCHANGE_ADDIN_DOC_URL arrives, the extension forwards the URL field directly to the native host com.trackersoftware.htmltopdf via chrome.runtime.connectNative, without validating the message origin. The extension also broadcasts its presence to every page on load, allowing any page script to detect it is installed.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

PDF-XChange Co. Ltd.v1.4.3Chrome Web Store
45Risk
Who publishes it

PDF-XChange Co Ltd. - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
PDF-XChange Co. Ltd.
Declared legal entity
PDF-XChange Co Ltd.
Registered address
PO Box 79, 9622 Chemainus Rd, Chemainus, BC V0R 1K0, CA
Registered contact
PDF-XChange Co Ltd.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 1.4.3. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    http://*/*

  • Read and change your data on every secure site you visit

    https://*/*

  • Save the full contents of any page you visit

    pageCapture

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

  • Add items to the right-click menu

    contextMenus

  • Store data in your browser

    storage

  • See the address and title of every tab you have open

    tabs

  • Run its own code inside the pages you visit

    scripting

Updated 30 September 2026blgipgnbmnikbdecnjmgckmndlkebhid