Is Адаптер Рутокен Web Плагин safe?
The extension injects a native messaging bridge to a Rutoken hardware PKI token into every web page, accessible to any page script.
Адаптер Рутокен Web Плагин runs a content script on all URLs that exposes the extension's runtime ID to page-level JavaScript and listens for postMessage commands. Any web page can send these messages to open a connection to the native host ru.rutokenweb.firewyrmhost, which interfaces with the Rutoken hardware PKI token. Because the extension ID is embedded in the injected stub and no origin check beyond e.source == window is applied, page scripts on any site can enumerate the token, list PKI plugins, and issue FireWyrmJS protocol commands to the native host.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 1.0.0.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging