Is 600% Sound Volume Booster safe?
600% Sound Volume Booster is high risk. Opening the popup makes wall.2.1.3.js create an invisible iframe to platform.micro-tools.online/paywall/784 with an ext_user_id from chrome.storage.sync, a persistent ID, letting the billing platform record popup use tied to your account.…
Who publishes itAliaksandr - 1 other listing from the same operator, none carrying a finding
Aliaksandr - 1 other listing from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
1 other listing published from this account, 10k+ users between them, none of them carrying a finding.
Shared hosts - 2 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Popup injects invisible iframe sending persistent visitor ID to billing platform
Opening the popup makes wall.2.1.3.js create an invisible iframe to platform.micro-tools.online/paywall/784 with an ext_user_id from chrome.storage.sync, a persistent ID, letting the billing platform record popup use tied to your account.
You open the extension popup.
popup.html loads wall.2.1.3.js unconditionally via a script tag.
The extension creates an invisible iframe that sends your persistent visitor ID to platform.micro-tools.online.
Dynamic analysis confirmed the iframe loaded and the billing platform received the ext_user_id parameter sourced from chrome.storage.sync.
Invisible iframe injection, wall.2.1.3.js
// wall.2.1.3.js — popup-context paywall client
// _userId was read from chrome.storage.sync key 'pw-784-visitor-id' during init()
_createAndAppendIframe: function() {
if (this._iframeCreated || this._iframeCreating) return;
this._iframeCreating = true;
window.requestAnimationFrame(() => {
const createIframe = () => {
const iframe = document.createElement('iframe');
// URL includes the persistent visitor ID as a query parameter
iframe.src = 'https://platform.micro-tools.online/paywall/'
+ this._paywallId
+ '?v=2.1.3&containerId=' + this.paywallContainerId
+ '&ext_user_id=' + this._userId; // persistent cross-session ID
iframe.id = 'paywall-' + this._paywallId;
// Styled to be invisible: zero dimensions, no border, opacity 0
iframe.style.cssText = 'position:fixed;width:0;height:0;border:none;opacity:0;';
const container = this.paywallContainerId
? (this._paywallDocumentRoot.getElementById(this.paywallContainerId)
|| this._paywallDocumentRoot.querySelector('body'))
: this._paywallDocumentRoot.querySelector('body');
if (container) {
container.appendChild(iframe);
this._iframeContentWindow = iframe.contentWindow;
this._iframeCreated = true;
this._iframeCreating = false;
}
};
if (this._paywallDocumentRoot.readyState === 'loading') {
this._paywallDocumentRoot.addEventListener('DOMContentLoaded', createIframe);
} else {
createIframe();
}
});
}| Field | Value | Why it matters | |
|---|---|---|---|
Visitor ID (ext_user_id) | a7f3e291-4bc2-4d88-b10c-8f2a1e6c3d90 | A persistent identifier from chrome.storage.sync included in the iframe URL each popup open, linking events to your account. | |
Wall version (v) | 2.1.3 | Paywall client version string included in the request URL, indicating which version of the billing client the extension is running. | |
Paywall ID | 784 | A numeric identifier for this extension's paywall instance at the billing platform. |
Target: popup.html body
An invisible iframe is appended to the popup body. Its src URL encodes the visitor ID as a query parameter and loads the billing platform on every popup open.
<body> <!-- Extension popup UI --> <div id="app"></div> </body>
<body>
<!-- Extension popup UI -->
<div id="app"></div>
<!-- Injected by wall.2.1.3.js — invisible to user -->
<iframe
id="paywall-784"
src="https://platform.micro-tools.online/paywall/784?v=2.1.3&containerId=&ext_user_id=a7f3e291-4bc2-4d88-b10c-8f2a1e6c3d90"
style="position:fixed;width:0;height:0;border:none;opacity:0;"
></iframe>
</body>- platform.micro-tools.online
Billing and paywall platform operated by the extension developer. Receives the persistent ext_user_id identifier via iframe URL on every popup open.