Is Synology Image Assistant Extension safe?

Low risk

Synology Image Assistant Extension accepts postMessage commands from any webpage, enabling relay to the local Synology desktop client.

The extension's content script, active on all websites, listens for postMessage events without validating the sender's origin. Any webpage can send an INIT_PORT message using the publicly readable message type constant to establish a communication channel. Once connected, the page can instruct the extension to fetch attacker-controlled URLs or forward data to the native Synology desktop application via native messaging.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Synology Inc.v1.0.33Firefox Add-ons
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Data recipients

com.synology.extension.host
Updated 17 September 2026amo-2841091