Is 600% Sound Volume Booster safe?

High risk

600% Sound Volume Booster is high risk. Opening the popup makes wall.2.1.3.js create an invisible iframe to platform.micro-tools.online/paywall/784 with an ext_user_id from chrome.storage.sync, a persistent ID, letting the billing platform record popup use tied to your account.…

Aliaksandrv3.1.6Chrome Web Store
75Risk
Who publishes it

Aliaksandr - 1 other listing from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Aliaksandr

Same store account

1 other listing published from this account, 10k+ users between them, none of them carrying a finding.

Shared hosts - 2 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

platform.micro-tools.online
Also called by 2 other listings, including TTS Reader
extaddon.site
Also called by 5 other listings, including Web Proxy Per Tab

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Popup injects invisible iframe sending persistent visitor ID to billing platform

Opening the popup makes wall.2.1.3.js create an invisible iframe to platform.micro-tools.online/paywall/784 with an ext_user_id from chrome.storage.sync, a persistent ID, letting the billing platform record popup use tied to your account.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open the extension popup.

popup.html loads wall.2.1.3.js unconditionally via a script tag.

The extension did this

The extension creates an invisible iframe that sends your persistent visitor ID to platform.micro-tools.online.

Dynamic analysis confirmed the iframe loaded and the billing platform received the ext_user_id parameter sourced from chrome.storage.sync.

02EvidenceNETWORK CAPTURE
Captured request
GEThttps://platform.micro-tools.online/paywall/784?v=2.1.3&containerId=&ext_user_id=<redacted>
Billing platform page loaded in iframe. Console logs from iframe JS confirmed '[PAYWALL IFRAME] PaywallClient mounted (hydrated)' and '[PAYWALL #784 v2.30.3] Sending state message'. 17 paywall console entries observed from iframe content at platform.micro-tools.online.
03EvidenceCODE COMPARE
The code that does this

Invisible iframe injection, wall.2.1.3.js

What it actually does
// wall.2.1.3.js — popup-context paywall client
// _userId was read from chrome.storage.sync key 'pw-784-visitor-id' during init()
_createAndAppendIframe: function() {
  if (this._iframeCreated || this._iframeCreating) return;
  this._iframeCreating = true;
  window.requestAnimationFrame(() => {
    const createIframe = () => {
      const iframe = document.createElement('iframe');
      // URL includes the persistent visitor ID as a query parameter
      iframe.src = 'https://platform.micro-tools.online/paywall/'
        + this._paywallId
        + '?v=2.1.3&containerId=' + this.paywallContainerId
        + '&ext_user_id=' + this._userId;  // persistent cross-session ID
      iframe.id = 'paywall-' + this._paywallId;
      // Styled to be invisible: zero dimensions, no border, opacity 0
      iframe.style.cssText = 'position:fixed;width:0;height:0;border:none;opacity:0;';
      const container = this.paywallContainerId
        ? (this._paywallDocumentRoot.getElementById(this.paywallContainerId)
           || this._paywallDocumentRoot.querySelector('body'))
        : this._paywallDocumentRoot.querySelector('body');
      if (container) {
        container.appendChild(iframe);
        this._iframeContentWindow = iframe.contentWindow;
        this._iframeCreated = true;
        this._iframeCreating = false;
      }
    };
    if (this._paywallDocumentRoot.readyState === 'loading') {
      this._paywallDocumentRoot.addEventListener('DOMContentLoaded', createIframe);
    } else {
      createIframe();
    }
  });
}
04EvidenceFIELD TABLE
Data transmitted to platform.micro-tools.online via iframe URL
FieldValueWhy it matters
Visitor ID (ext_user_id)
a7f3e291-4bc2-4d88-b10c-8f2a1e6c3d90A persistent identifier from chrome.storage.sync included in the iframe URL each popup open, linking events to your account.
Wall version (v)
2.1.3Paywall client version string included in the request URL, indicating which version of the billing client the extension is running.
Paywall ID
784A numeric identifier for this extension's paywall instance at the billing platform.
05EvidenceDOM DIFF
Page DOM modified

Target: popup.html body

An invisible iframe is appended to the popup body. Its src URL encodes the visitor ID as a query parameter and loads the billing platform on every popup open.

Before
<body>
  <!-- Extension popup UI -->
  <div id="app"></div>
</body>
After (modified by extension)
<body>
  <!-- Extension popup UI -->
  <div id="app"></div>
  <!-- Injected by wall.2.1.3.js — invisible to user -->
  <iframe
    id="paywall-784"
    src="https://platform.micro-tools.online/paywall/784?v=2.1.3&containerId=&ext_user_id=a7f3e291-4bc2-4d88-b10c-8f2a1e6c3d90"
    style="position:fixed;width:0;height:0;border:none;opacity:0;"
  ></iframe>
</body>
06EvidenceTHIRD PARTY LIST
Domain receiving the visitor ID
  • platform.micro-tools.online

    Billing and paywall platform operated by the extension developer. Receives the persistent ext_user_id identifier via iframe URL on every popup open.

Updated 30 September 2026kcgedkeajhbfkackhppmenimpfpnopje