Is Auto Refresh Page - Reload Pages Automatically & Page Monitor Easily safe?

Medium risk

Auto Refresh Page is medium risk. We observed the extension validate its license with auto-refresh.extfy.com after startup, POSTing and reading flags (valid/success/status). It writes a feature-state value background/popup use for premium behavior or locked limits.

Softpulse Infotechv1.0.36Chrome Web Store
45Risk
Who publishes it

Softpulse Infotech - 2 other listings from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Softpulse Infotech

Same store account

2 other listings published from this account, 3k+ users between them, none of them carrying a finding.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-829
SourceAI SANDBOX

Remote License Response Controls Premium Features

We observed the extension validate its license with auto-refresh.extfy.com after startup, POSTing and reading flags (valid/success/status).

It writes a feature-state value background/popup use for premium behavior or locked limits.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You start Chrome with the extension installed.

The extension can run this license validation automatically without a separate prompt.

The extension did this

It asks a remote license server whether premium behavior should remain enabled.

The response updates the local feature-state value that later controls locked and enabled options.

02EvidenceNETWORK CAPTURE
Captured request
POSThttps://auto-refresh.extfy.com/lempay/validate.php
03EvidenceFIELD TABLE
Fields that drive the remote feature check
FieldValueWhy it matters
Stored license key
license_key=<redacted>This value identifies the subscription being validated. It is sent to the remote server during the check.
Extension version
extension_version=1.0.32This tells the server which installed release is asking for validation.
Validation action
type=validateThis marks the request as a license validation check rather than feedback or another endpoint action.
Server decision fields
valid=false, status=errorThese response values decide whether the extension treats the license as enabled or locked.
Local feature-state value
_subc_pd_dgsp=ntvdThis local value is read later to decide whether premium controls stay available.
04EvidenceCODE COMPARE
The code that does this

The startup validation path posts the license and stores the feature state

What it actually does
Endpoint and storage-key constantsjs/background.js
const g = "https://softpulseinfotech.com/extensions/auto_refresh/feedback.php",
  y = "https://auto-refresh.extfy.com/feedback.php",
  v = "https://auto-refresh.extfy.com/lempay/validate.php",
  k = "_werptrg_dpo",
  x = "_srbop_ikf",
  I = "_rtyio_fghj",
  T = "_serub_k_dgsp",
  S = "_subc_pd_dgsp",
  M = "_fxyz_s";
let O = "_opn_eqaf",
  E = atob,
  R = btoa,
  U = !1,
  A = 0,
  q = 0;
chrome.storage.local.get([x, O, S], function(e) {
  try {
    e && "vd" == e[S] && (U = !0);
    var t = e && e[x] ? parseInt(re(e[x])) : 0;
    t > A && (A = t);
    var r = e && e[O] ? parseInt(re(e[O])) : 0;
    r > q && (q = r)
  } catch (e) {}
});
Startup license validation and feature-state updatejs/background.js
z(), chrome.runtime.onStartup.addListener(function() {
  !async function() {
    const e = (await chrome.storage.local.get([Q]))[Q];
    if (e && Date.now() - e.timestamp < D) return e.value;
    const t = await async function() {
      let e = await chrome.storage.local.get([T, S, M]);
      if (void 0 === e[T] || null === e[T] || "" === e[T]) return U = !1, ae("ntvd", S), !1;
      try {
        var t = chrome.runtime.getManifest().version;
        let n = _e(e[T].slice(4, -3)),
          o = Date.now();
        var r = await fetch(`${v}?${o}`, {
          method: "POST",
          body: new URLSearchParams({
            license_key: n,
            type: "validate",
            extension_version: t
          })
        });
        if (!r.ok) throw new Error(`HTTP error! Status: ${r.status}`);
        if (e = await r.json(), !0 === e?.valid || 1 == e?.success) return chrome.storage.local.set({
          [S]: "vd"
        }), U = !0, !0;
        if (!1 === e?.valid || "error" === e?.status) {
          let e = {
            [S]: "ntvd"
          };
          return chrome.storage.local.set(e), U = !1, ae("ntvd", S), !1
        }
        return U = !0, !0
      } catch (e) {
        return U = !0, !0
      }
    }();
    await chrome.storage.local.set({
      [Q]: {
        value: t,
        timestamp: Date.now()
      }
    })
  }(), chrome.storage.local.get(["data", "btn_status_k", x, O, S], function(e) {
    var r = e.data;
    if (U = "vd" == e[S], A = e[x] ? re(e[x]) : 0, q = e[O] ? re(e[O]) : 0, null != r) {
      var n = [],
        o = [];
      unique = r.filter(t => (t.refreshType = t.refreshType ? t.refreshType : "manual_url", "manual_url" !== t.refreshType || n.includes(t.tab_url) ? "current_tab" === t.refreshType : (n.push(t.tab_url), null != t.automatic_start_refresh && 1 == t.automatic_start_refresh && "unchecked" !== e.btn_status_k && (t.btn_start = 1), o.push(t), !0))), t = o, o.forEach(t => {
        1 == t.auto_open_url_on_browser_start && "manual_url" === t.refreshType && "unchecked" !== e.btn_status_k && (q < parseInt(re("WfGYMzAxTKJ")) || !0 === U) && (t.btn_start = 1, q++, chrome.storage.local.set({
          [O]: ne(q)
        }), ae(ne(q), O), chrome.tabs.create({
          url: t.url
        }))
      }), chrome.storage.local.set({
        data: o
      }, function() {
        z()
      })
    } else z()
  }), chrome.storage.local.set({
    payment_tab_id: "",
    help_tab_id: "",
    import_window_id: "",
    import_sound_window_id: "",
    settings_tab_id: ""
  })
05EvidenceTHIRD PARTY LIST
Remote host involved in the feature-state decision
  • auto-refresh.extfy.com

    Receives the license-validation POST and returns fields that the extension uses to set the local premium feature state.

Updated 30 September 2026aipbahhkojbhioodfbfmnobjnkagpnfg