Is Vinova Encryption Plugin safe?

Low risk

Vinova Encryption Plugin bridges every website to a local native host, checking only that messages share the page window, not their origin.

A content script loaded on every http and https page relays window messages to a local native encryption helper (com.fastnsafe.firewyrmhost_dev) through the extension's background script, forwarding them verbatim in both directions. It checks only that a message came from the same browser window, not that the page is one the vendor trusts, so a script running on any site can open this bridge to the native host. Whether the native host itself independently requires a PIN before acting on those messages could not be confirmed from the extension's code alone.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

katechoo.sgv0.0.5Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Data recipients

com.fastnsafe.firewyrmhost_dev (local native messaging host)
Updated 20 September 2026klhlbnjjpdpapjmclmlohipmnjepcnnm