Is PDF-XChange safe?
PDF-XChange relays unvalidated postMessage URLs from any page script to a native host application on the user's computer.
The extension injects a content script into every page and listens for postMessage events. When a message with type PDFXCHANGE_ADDIN_DOC_URL arrives, the extension forwards the URL field directly to the native host com.trackersoftware.htmltopdf via chrome.runtime.connectNative, without validating the message origin. The extension also broadcasts its presence to every page on load, allowing any page script to detect it is installed.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itPDF-XChange Co Ltd. - no other listings under this identity
PDF-XChange Co Ltd. - no other listings under this identity
What this publisher told the store about itself, and the other listings that told it the same thing.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 1.4.3. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
http://*/*
Read and change your data on every secure site you visit
https://*/*
Save the full contents of any page you visit
pageCapture
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
Add items to the right-click menu
contextMenus
Store data in your browser
storage
See the address and title of every tab you have open
tabs
Run its own code inside the pages you visit
scripting