Is Audio editor online X-Audacity safe?

High risk

Audio editor online X-Audacity transmits every visited URL, hex-encoded, to offidocs.com along with a persistent per-installation tracking ID.

On every tab activation and update, the extension captures the full URL of any non-offidocs.com page and sends it to a tracking endpoint at www.offidocs.com. Each installation is assigned a random 10-character ID on first run, stored in local storage, and included with every request — enabling per-user browsing history collection. This behavior is on by default and can only be disabled by the user toggling a local storage flag.

officeonlinesystemsv2.15.3Chrome Web Store
75Risk
Who publishes it

officeonlinesystems - 26 other listings from the same operator, 17 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
officeonlinesystems
Registered address
Av. Dr. Arce 43, Madrid 28002, Spain

Shared hosts - 1 hostname

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

offidocs.com
Also called by 7 other listings, including Image editor PaintMagick for photos, PhotoStudio, Encrypt any email with CipherMail

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Audio editor extension transmits every visited URL to offidocs.com

The extension sends the address of every site you visit to www.offidocs.com, paired with a persistent 10-char ID.

Fires on tab switch/navigation, all sites, no interaction.

Confirmed: hex-encoded GETs left within seconds.

On by default.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open or switch to any website in your browser.

Any HTTP or HTTPS tab, including background tabs you click into, triggers the request. Only offidocs.com pages and non-HTTP URLs (chrome://, file://) are excluded.

The extension did this

The extension sends your full visited URL and a persistent tracking identifier to www.offidocs.com.

The request fires automatically with no user interaction beyond normal browsing. The tracking flag defaults to enabled on installation.

02EvidenceNETWORK CAPTURE
Captured request
GEThttps://www.offidocs.com/media/system/app/checkdownloadaudacityx_3_nav.php?filepath=68747470733a2f2f7777772e6578616d706c652e636f6d2f70616765&hex=1&u=hyclrbnmvb
Dynamic analysis observed 16 GET requests matching this pattern across 4 distinct sites visited in a single session. A planted marker value was transmitted to offidocs.com and appeared hex-decoded in the filepath parameter, confirming that live visited URLs leave the browser.
03EvidenceOPAQUE REVEAL
Why you can't catch this in DevTools

The visited URL is hex-encoded one character at a time before appearing in the filepath query parameter. The encoding is trivially reversible and provides no privacy.

What's actually being sent
https://www.example.com/page
04EvidenceFIELD TABLE
Data sent to offidocs.com on every navigation
FieldValueWhy it matters
Visited URL (hex-encoded)
filepath=68747470733a2f2f7777772e6578616d706c652e636f6d2f70616765 (decodes to https://www.example.com/page)The complete address of every page you open or switch to, sent as the filepath parameter, including banking, medical, or internal sites.
Installation tracking ID
u=hyclrbnmvbA random 10-char ID from first run, stored permanently, sent on every request, letting the server tie all your browsing to one install.
05EvidenceCODE COMPARE
The code that does this

Navigation listener and URL transmission, websecure.js

What it actually does
Tab event listeners and filter logic — annotatedwebsecure.js
// Called on every tab switch (onActivated) and every page navigation (onUpdated).
// Filter: HTTP/HTTPS only; skips offidocs.com itself; deduplicates consecutive same-URL events.
async function getTabInfo(tabId) {
    const tab = await new Promise((resolve, reject) => {
        chrome.tabs.get(tabId, (tab) => tab ? resolve(tab) : reject(new Error("Tab not found")));
    });

    if (
        !tab.url.includes("offidocs") &&  // exclude the developer's own domain
        tab.url.startsWith("http") &&      // only HTTP/HTTPS; ignores chrome:// and file://
        lastUrl !== tab.url               // skip if same URL was just sent (simple dedup)
    ) {
        lastUrl = tab.url;
        extractaudio(tab.url, tabId);     // transmit the visited URL to offidocs.com
    }
}

class WebSecure {
    init() {
        // Register on both events to capture tab switches AND in-tab navigations
        chrome.tabs.onActivated.addListener(activeInfo => {
            activeTabId = activeInfo.tabId;
            getTabInfo(activeTabId);
        });

        chrome.tabs.onUpdated.addListener((tabId, changeInfo, tab) => {
            getTabInfo(tabId);
        });
    }
}
URL transmission and tracking ID management — annotatedwebsecure.js
async function extractaudio(urlxx, tabId) {
    try {
        const offidocs_key = "offidocs_key";
        // Read tracking ID and enabled flag from persistent local storage
        let { username: storedUsername, offidocscloud } = await chrome.storage.local.get(offidocs_key);
        
        if (!storedUsername) {
            // First run: generate a random 10-char lowercase ID and default tracking to enabled
            storedUsername = randomString(10).toLowerCase();
            await chrome.storage.local.set({ 
                [offidocs_key]: { 
                    username: storedUsername,
                    offidocscloud: "1"  // '1' = enabled; this is the out-of-box default
                } 
            });
        }

        // Only suppressed if the user explicitly toggled the flag to "0" in the popup
        if (offidocscloud === "0") return;

        // Hex-encode the visited URL and send it with the persistent tracking ID
        const response = await fetch(
            `https://www.offidocs.com/media/system/app/checkdownloadaudacityx_3_nav.php?filepath=${bin2hex(urlxx)}&hex=1&u=${storedUsername}`
        );

    } catch (error) {
        console.error("Audio extraction failed:", error);
    }
}

// Trivially reversible hex encoding applied to every visited URL
function bin2hex(bin) {
    return Array.from(bin).map(c => 
        c.charCodeAt(0).toString(16).padStart(2, '0')
    ).join('');
}
06EvidenceARTIFACT
Check if you're affected

Decodes the hex-encoded filepath parameter found in GET requests to offidocs.com, letting you verify that URLs in your own proxy or browser network logs correspond to websites you actually visited.

RequiresNode.js 14+
decode-offidocs-filepath.js · js
#!/usr/bin/env node
// decode-offidocs-filepath.js
//
// Decodes the hex-encoded 'filepath' query parameter from GET requests to:
//   https://www.offidocs.com/media/system/app/checkdownloadaudacityx_3_nav.php
//
// Capture the request in your browser's DevTools Network panel or a proxy,
// copy the value of the 'filepath' query parameter, and pass it here.

const hex = process.argv[2];

if (!hex) {
  console.error('Usage: node decode-offidocs-filepath.js <filepath_hex_value>');
  console.error('');
  console.error('Example:');
  console.error('  node decode-offidocs-filepath.js 68747470733a2f2f7777772e6578616d706c652e636f6d2f70616765');
  console.error('  → https://www.example.com/page');
  process.exit(1);
}

if (!/^[0-9a-fA-F]+$/.test(hex)) {
  console.error('Error: input must be a hex string (characters 0-9, a-f, A-F only)');
  process.exit(1);
}

try {
  const decoded = Buffer.from(hex, 'hex').toString('utf8');
  console.log('Decoded visited URL:', decoded);
} catch (err) {
  console.error('Failed to decode:', err.message);
  process.exit(1);
}
How to run it
  1. 1
    node decode-offidocs-filepath.js <hex_value>, where <hex_value> is the filepath query parameter copied from a captured GET request to offidocs.com/media/system/app/checkdownloadaudacityx_3_nav.php
07EvidenceTHIRD PARTY LIST
Network destination
  • www.offidocs.com

    Receives the hex-encoded visited URL and the tracking ID via checkdownloadaudacityx_3_nav.php. Operated by the party that publishes X-Audacity on the Chrome Web Store.

Where it sends data

Destinations our analysis observed X-Audacity contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • www.offidocs.com

    X-Audacity sends data to www.offidocs.com. 11 other extensions we have analysed send data here.

Updated 30 September 2026jaembmdeobjibglbnnefpalabeohjpnj