Is TrustPlugin safe?

Low risk

TrustPlugin relays page messages to a native PKI host without origin validation, exposing certificate enumeration and signing to any site.

The extension injects a content script into every page that listens for window.postMessage messages and forwards them to a native application (chrome.trust.plugin) without checking where the message came from. The native host exposes operations including enumerating installed PKI tokens and certificates, reading IP configuration, and triggering GOST digital signatures using the user's private key. Any webpage can send a crafted message to initiate these operations and receive the results back via postMessage.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Инфотекс Интернет Трастv1.3.9.0Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 1.3.9.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    <all_urls>

  • Store data in your browser

    storage

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

  • Show you desktop notifications

    notifications

Updated 30 September 2026pijnjbgfjklnneejaijciijloogicfkn