Is Web eID safe?

Low risk

Web eID exposes eID card certificate retrieval and signing to all web pages via an unvalidated postMessage interface.

The extension injects a TokenSigning compatibility API and a web-eid: action handler into every page it runs on. The postMessage listener accepts authenticate, sign, and get-signing-certificate commands from any same-window script without checking the message origin, relaying them to the native app eu.webeid. This means scripts running alongside the extension — including injected ad scripts or XSS payloads — can request the user's X.509 signing certificate (which contains name and national ID code) or trigger a digital signature operation.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

riaeev2.5.0Chrome Web Store
20Risk
Who publishes it

Riigi Infosüsteemi Amet - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
riaee
Declared legal entity
Riigi Infosüsteemi Amet
Registered address
Pärnu mnt 139a, Tallinn 11317, EE

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Updated 30 September 2026ncibgoaomkmdpilpocfeponihegamlic