Is SPM File Edit Native Messaging Bridge safe?

Low risk

SPM File Edit relays postMessage commands from any page to a local native messaging host with no origin validation.

The extension injects a content script on all HTTP and HTTPS pages that listens for window.postMessage events typed PAGE_2_EXTN. Any page script can send these messages, and the content script forwards the commands — including caller-supplied file parameters — through to the native host 'curam.fileedit.chrome.nativebridge' running on the user's machine. The native host is a local Word document editing bridge; no data is sent to remote servers.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

spm-chromev3.0.0.1Chrome Web Store
20Risk
Who publishes it

Merative Heathcare Ireland - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
spm-chrome
Declared legal entity
Merative Heathcare Ireland
Registered address
3rd floor block B, Central Quay, Riverside IV, Dublin, Co. Dublin D02 NY19, IE
Registered contact
Cúram

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 3.0.0.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    http://*/*

  • Read and change your data on every secure site you visit

    https://*/*

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

  • Keep running in the background while your browser is open

    background

Updated 30 September 2026chefnfmmodjpepjmmdehfapjafboobhe