Is Billfish - Free material management tool safe?
Billfish is medium risk. Billfish's popup and in-page prompts send events via the bundled SensorsData SDK to sa.aunload.com. A captured BTriggerWindow POST held browser/version data, screen details, a prompt name, and page context. hm.baidu.com is also allowed.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Behavior events reach external analytics endpoints
Billfish's popup and in-page prompts send events via the bundled SensorsData SDK to sa.aunload.com.
A captured BTriggerWindow POST held browser/version data, screen details, a prompt name, and page context. hm.baidu.com is also allowed.
You open Billfish or trigger one of its in-page collection prompts.
The popup and content script create named behavior events when these UI paths run.
The extension forwards the event name and page-context fields to an external analytics collector.
Dynamic analysis captured the resulting SensorsData request to `sa.aunload.com`.
| Field | Value | Why it matters | |
|---|---|---|---|
Event name | BTriggerWindow | Shows which extension behavior was recorded about your interaction. | |
Prompt or interaction name | pc_Tip_name: PopupDialog | Identifies the specific Billfish prompt or collection action shown while you browse. | |
Browser details | Chrome 126.0.6478.127 (illustrative value; field observed) | Adds device context that can help separate your browser from other users' browsers. | |
Screen and viewport | 1920x1080 screen, 1280x720 viewport (illustrative value; field observed) | Adds display-size context to the behavior event sent about your session. | |
Extension page context | chrome-extension://piohkopmiebhgodfkcfcmjbmgkcnjnmf/background.js | Ties the event to the Billfish extension context instead of a normal website page. |
How the event is created, handed to the background script, and sent
async sendToSa(e, t) {
this.backCaller.call(j.SendToSa, {
id: e,
sendData: t
})
}
return async function() {
const e = {
pc_Tip_name: L.PopupDialog
};
ge.sendToSa("BTriggerWindow", e);
const t = await he.getConfig({
appId: z,
appVersion: "4.0.5"
});
g.value = t[0], g.value.version > "4.0.5" && (o.value = !0)
}()openBillfishDom() {
try {
this.backCaller.call(Z.SendToSa, {
id: "BTriggerWindow",
sendData: {
pc_Tip_name: R.OpenBillfish
}
});
return '\n <div class="billfish-no-detect-bac" id="billfishNoDeetctBac" style="z-index: 99999999999999">\n <div class="billfish-all-tips">\n <div id="open-billfish" class="tips-open-buttom">打开Billfish</div>\n </div>\n </div>\n '
} catch (e) {
console.log(e)
}
}Object.assign(fe.para_default, {
send_type: "beacon"
}), fe.init({
send_type: "beacon",
server_url: "https://sa.aunload.com:4006/sa?project=production",
use_app_track: !0,
show_log: false,
heatmap: {
clickmap: "not_collect",
scroll_notice_map: "not_collect"
}
});
this.invoker.bind(Br.SendToSa, (async e => {
we.setSensors(e.input.id, e.input.sendData)
}));
sendData: function(e, t) {
var r = se(e.properties);
!0 === Wt.para.debug_mode ? (Wt.log(e), Wt.saEvent.debugPath(JSON.stringify(e), t)) : Wt.sendState.getSendCall(e, r, t)
},
encodeTrackData: function(e) {
var t = E(e),
r = "crc=" + C(t);
return "data=" + encodeURIComponent(t) + "&ext=" + encodeURIComponent(r)
}
Lr.sendCall = function(e, t, r) {
var n = {
server_url: t,
data: JSON.stringify(e.data),
callback: r,
config: e.config
};
h(Wt.para.jsapp) && !Wt.para.jsapp.isOnline && "function" == typeof Wt.para.jsapp.setData ? (delete n.callback, n = JSON.stringify(n), Wt.para.jsapp.setData(n)) : this.realtimeSend(n)
}- sa.aunload.com
SensorsData collector that received the observed `BTriggerWindow` event over HTTPS.
- hm.baidu.com
Baidu Analytics host embedded in the background script's external endpoint list.
What it can do
Permissions this extension asks for, as declared in version 4.0.5. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
http://*/*
Read and change your data on every secure site you visit
https://*/*
See the address and title of every tab you have open
tabs
Store data in your browser
storage
Act on the current tab, but only after you click the extension
activeTab
Watch every request your browser makes
webRequest
Run its own code inside the pages you visit
scripting
Add items to the right-click menu
contextMenus