Is TrustPlugin safe?
TrustPlugin relays page messages to a native PKI host without origin validation, exposing certificate enumeration and signing to any site.
The extension injects a content script into every page that listens for window.postMessage messages and forwards them to a native application (chrome.trust.plugin) without checking where the message came from. The native host exposes operations including enumerating installed PKI tokens and certificates, reading IP configuration, and triggering GOST digital signatures using the user's private key. Any webpage can send a crafted message to initiate these operations and receive the results back via postMessage.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 1.3.9.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
<all_urls>
Store data in your browser
storage
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
Show you desktop notifications
notifications