Is SroDotNetActivator safe?

Low risk

SroDotNetActivator bridges any web page containing a specific DOM marker element to a locally installed .NET native messaging host.

The extension's content script runs on all HTTP, HTTPS, and local file pages. When a page contains an element with the ID 'SroDotNetActivatorExtensionMarker', the script opens a native messaging channel to the locally installed 'srodotnetactivator' host and relays any window.postMessage calls from that page—or from iframes—to the native host without origin validation. Replies from the native host are posted back to the page via window.postMessage with a wildcard target origin.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

sro.automationv4.2.2Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 4.2.2. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Updated 30 September 2026cakpdcgfiopmmimbfdoljkengnmfjmpo