Is Signer.Digital Digital Signature, PKI safe?

Medium risk

Signer.Digital exposes a postMessage bridge on every page that any website can use to relay commands to a local native PKI host.

The extension injects a script into all pages that exposes a window.SignerDigital API, allowing any website to call methods that retrieve smart card certificate details including name, email, organisation, and thumbprint. Content scripts relay postMessage events to the background page, which forwards them without filtering to the native host signer.digital.chrome.host. Because the only gate is a constant string (src: 'user_page.js') that ships inside the extension's web-accessible resources, any page can craft matching messages and invoke arbitrary native messaging commands.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Chartered Information Systems Pvt. Ltd.v5.3.0Chrome Web Store
45Risk
Who publishes it

Chartered Information Systems Pvt. Ltd. - no other listings under this identity, 3 shared hostnames

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Chartered Information Systems Pvt. Ltd.
Declared legal entity
Chartered Information Systems Pvt. Ltd.
Registered address
Chartered House, West of Lata Mangeshkar Park, Bhandara Road, Nagpur, Maharashtra 440035, IN
Registered contact
Chartered Information Systems Pvt. Ltd.

Shared hosts - 3 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

downloads.signer.digital
Also called by 3 other listings, including Signer.Digital Digital Signature, PKI
signer.digital
Also called by 3 other listings, including Signer.Digital Digital Signature, PKI
web.signer.digital
Also called by 3 other listings, including Signer.Digital Digital Signature, PKI

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 5.1.2. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 5.3.0, which we have not unpacked yet.

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Our write-ups

Updated 30 September 2026glghokcicpikglmflbbelbgeafpijkkf