Is Topaz SigPlusExtLite Extension safe?

Medium risk

Topaz SigPlusExtLite exposes a biometric signature-pad bridge to every website with no origin restriction.

The extension injects content scripts into all pages and listens for CustomEvents that any page can dispatch. When triggered, it relays commands to the Topaz native host (com.topaz.sigplusextlite.win.2), which drives a physical signature pad and returns the captured signature image, raw pen data, and signature string back to the requesting page. A separate command path allows any page to trigger a JPEG screen capture of a secondary GemView display window, with the result returned to the page via the same CustomEvent channel.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Topaz Systems Incv3.1.16.5Chrome Web Store
45Risk
Who publishes it

Topaz Systems, Inc. - 2 other listings from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Topaz Systems Inc
Declared legal entity
Topaz Systems, Inc.
Registered address
875 Patriot Dr Unit A, Moorpark, CA 93021-3351, US
Registered contact
Tony Zank

Same store account

2 other listings published from this account, 210k+ users between them, none of them carrying a finding.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 3.1.16.5. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    <all_urls>

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

  • Keep running in the background while your browser is open

    background

  • Read information about your displays

    system.display

Updated 30 September 2026dhcpobccjkdnmibckgpejmbpmpembgco