Chrome Web Store
3Versions
1Code reviewed

No malware found

In code review (v1.0.66.5541)

Our reviewer read version 1.0.66.5541 — the most recent version we have reviewed — and found no malicious behaviour. The version shown here has not been individually reviewed yet.

What our analysis found

Imprivata Enterprise Access Management, used by 20,000,000 people, showed no malicious code in Extension Auditor's review. Its permissions mean it can inject scripts into pages and can observe network requests. It was last updated in February 2026.

Imprivata Enterprise Access Management is a well-known enterprise SSO product from Imprivata Inc., a legitimate US-based healthcare IT security vendor. All code reviewed implements a clean, comment-rich native-messaging bridge between the Chrome extension and a locally-installed Imprivata Agent desktop application (com.imprivata.isxnmhost). Credentials captured from web login forms are immediately encrypted client-side using libsodium's crypto_box_easy (NaCl public-key encryption with a per-session key exchange) before being relayed over native messaging — they are never transmitted to any remote server, and no network calls to external domains appear anywhere in the source. The ML model flagged broad permissions (scripting, webRequest, nativeMessaging, all-host content scripts) and common SSO implementation patterns (form-field listeners, document.createElement('script') for injecting from the extension's own origin) that are inherent and necessary for an enterprise SSO product of this kind, not indicators of malice.

Imprivata Enterprise Access Management

Imprivata Enterprise Access Management

ID: bpgncafocbpieaeigfcookhgmeamglgo

Supported Languages

🇺🇸English

Extension Info & Metadata

Status
Active
Version
25.4.000.15
Size
0.24 MB
Rating
3.0/5
Reviews
19
Users
20,000,000
Type
Extension
Updated
Feb 9, 2026
Category
Privacy & security
Price
Paid
Featured
No
Visibility
Unlisted
Mature
No
By Google
No
Trusted
No
This publisherTrack record
1extension
All still listed
Scanned by Extension Auditor — Low RiskDevelopers: embed this badge to link to this report.

Publisher Contextual Analysis

Author
Imprivata, Inc.View Profile
Country
US
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
Yes
Mailbox exists
Yes
Address
6th floor 20 CityPoint, 480 Totten Pond Rd Waltham, MA 02451 US
Website
Visit
Extensions
1
Active
1
Obsolete
0
Listed
0
Unlisted
1
Users
20,000,000

Screenshots & videos

Screenshot 1

Install growth

Item
Type
Severity
Description
scripting
Permission
Critical
This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to.
webRequest
Permission
Critical
This permission enables the extension to monitor and analyze all web requests made by the browser. Rated Critical because it can observe all network traffic including sensitive data, track browsing behavior, and gather authentication tokens.
http://*/*
Host
Critical
Broad host access — the extension can read/modify content on every website.
https://*/*
Host
Critical
Broad host access — the extension can read/modify content on every website.
nativeMessaging
Permission
High
This permission enables communication with applications installed on your computer. Rated High because it can exchange data with native programs, potentially exposing system-level information and local files.
webNavigation
Permission
High
This permission enables monitoring of all browser navigation events and transitions. Rated High because it can track every page visit, navigation method, and browsing pattern, potentially exposing sensitive browsing behavior and user activities.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 10% increase: Early script execution enables pre-emptive content manipulation
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
activeTab
Permission
Medium
This permission grants temporary access to the current tab. Rated Medium because it can access current page content when invoked, though limited to user-initiated actions.
Early Content Script Execution
Risk Factor
Medium
This extension runs content scripts at document_start.

Gain full insight into all external connections.

Upgrade for full visibility.

About this extension

Provides Single Sign-On for Google Chrome and Microsoft Edge

Read the publisher’s full description

This is the Chrome extension that the Imprivata Agent installer automatically downloads from the Chrome Web Store. The Chrome extension communicates with the Imprivata Agent to enable single sign-on for web applications running in the Chrome browser. This extension should not be installed manually.

User reviews

Extension files

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.

URLs
1

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

No URLs found
No IP addresses found

Gain full insight into all external connections.

Upgrade for full visibility.

Version
Size
Verdict
Findings
Permhash
25.4.000.15
Latest
0.24 MBNot scanned—
1.0.66.5541
0.25 MBNo malware found0
1.0.71.2904
0.24 MBNot scanned—
Showing 1 to 3 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files detected

No comparable text files found between these versions.

Gain full insight into all external connections.

Upgrade for full visibility.

Popular in Privacy & Security