Is SADocumentExtension safe?

Low risk

SADocumentExtension relays arbitrary CustomEvent payloads from any web page to the native host sa.document.extension with no filtering.

The extension injects a content script into all web pages that listens for a CustomEvent named 'SentDocumentLink'. Any page can dispatch this event with arbitrary data, which the content script forwards to the background page; the background page then passes the payload directly to the native host sa.document.extension via chrome.runtime.sendNativeMessage without validation. This means untrusted web content can send arbitrary messages to the native application installed on the user's device.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

SmartAdvocatev1.4Chrome Web Store
20Risk
Who publishes it

SmartAdvocate - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
SmartAdvocate

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 1.4. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    *://*/*

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Where it sends data

Destinations our analysis observed SADocumentExtension contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • sa.document.extension (native host)

    SADocumentExtension sends data to sa.document.extension (native host). Named as a recipient in this extension's own analysis.

Updated 30 September 2026ofcdbngfnpdlmdligcclbkihfbahdnph