Is Calculator safe?
Calculator is high risk. Calculator's background service worker fetches a JSON configuration file from otsledit.net every time it starts, before you load any page. The file supplies the domain rules and link-rewrite prefixes used elsewhere in the extension.…
Who publishes itPrice Tracker - 1 other listing from the same operator, 1 of them carrying a finding
Price Tracker - 1 other listing from the same operator, 1 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
1 other listing published from this account, 20k+ users between them. 1 of them carries a finding.
Shared hosts - 2 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Calculator fetches a remote config file that can rewrite links on any page
Calculator's background service worker fetches a JSON configuration file from otsledit.net every time it starts, before you load any page.
The file supplies the domain rules and link-rewrite prefixes used elsewhere in the extension.
You start Chrome with the Calculator extension installed.
The background service worker immediately requests a configuration file from otsledit.net, before any page has loaded.
The response supplies the domain-matching rules and link-rewrite prefixes used elsewhere in the extension.
| Accept | application/json |
| Content-Type | application/json |
| Field | Value | Why it matters | |
|---|---|---|---|
Site matching pattern | matches include aliexpress.com, banggood.com (observed) | A regular expression tested against every page you visit. Only matching pages trigger the redirect and link-rewrite logic. | |
Redirect destination list | ["aliexpress.com", "https://otsledit.net/r?u="] (observed) | 3,808 domain and URL-prefix pairs. Your page's own URL gets the matching prefix glued on the front, then the browser is sent there. | |
Per-link rewrite rules | defaultMinor.al: [timestamp_key, link_pattern, affiliate_prefix] | A separate rule list for links already on the page. Clicking a matching link briefly rewrites its destination, then restores it. | |
Redirect cooldown | localStorage['ckAli'], 259,200-second cooldown | Once a redirect fires on a device, a timestamp is stored so the same device is not redirected again for 3 days. |
The service worker's startup fetch and message handler
// State that the extension itself never populates with fixed values.
// It is entirely filled in from whatever otsledit.net returns.
let siteMatchPattern = []; // was: defaultMatches
let redirectRules = []; // was: defaultLinks
let altRedirectRule = []; // was: defaultSLink
let perLinkRules = []; // was: defaultMinor
// Runs on every service worker start, before any page loads.
fetch("https://otsledit.net/calc", { method: 'GET', headers: { Accept: 'application/json', 'Content-Type': 'application/json' } })
.then(r => r.json())
.then(remoteConfig => {
// No local validation of remoteConfig's content beyond presence checks.
// Whatever the server sends becomes the extension's active behavior.
siteMatchPattern = remoteConfig.defaultMatches;
redirectRules = remoteConfig.defaultLinks; // 3,808 entries observed
altRedirectRule = remoteConfig.defaultSLink;
perLinkRules = remoteConfig.defaultMinor;
});
// content.js asks for this data via chrome.runtime.sendMessage({start:true})
// on every page load and gets back exactly what the remote server sent.
chrome.runtime.onMessage.addListener((request, sender, sendResponse) => {
if (siteMatchPattern && redirectRules && request.start) {
sendResponse({
defaultMatches: siteMatchPattern,
defaultLinks: redirectRules,
defaultSLink: altRedirectRule,
defaultMinor: perLinkRules
});
}
});- otsledit.net
Supplies the live domain-match pattern and 3,808 redirect-prefix pairs that determine Calculator's link and page-redirect behavior. Not a resource a calculator app needs.
Calculator redirects shopping-site visits through an affiliate link chain
When you open a shopping site matched by Calculator's remote config, such as AliExpress or Banggood, the extension replaces the page with an affiliate-prefixed version of the same URL and stores a timestamp so it does not repeat for 3 days.
You navigate to a shopping site the extension's remote config matches, such as aliexpress.com or banggood.com.
The content script replaces the current page with an affiliate-prefixed version of the same URL and records a 3-day cooldown.
window.location.href is set to the config's redirect prefix plus the page's own URL, so the browser navigates through the affiliate link before the original page ever renders.
| Field | Value | Why it matters | |
|---|---|---|---|
Original page | https://www.aliexpress.com/ | The shopping site you actually navigated to. | |
Redirect prefix added | https://otsledit.net/r?u= | Text placed in front of your page's URL before the browser is sent there. | |
Final landing host | alitems.com (from aliexpress.com); ad.admitad.com (from banggood.com) | Where the redirect ends up, carrying an affiliate attribution tag for the site you were already visiting. | |
Cooldown marker | localStorage['ckAli'] | A per-device timestamp that stops the same browser from being redirected again for 3 days. |
The content script's redirect check
// True unless a redirect already fired on this device within the last
// 259,200 seconds (3 days).
var cooldownExpired = checkTime('ckAli');
chrome.runtime.sendMessage({ start: true }, remoteConfig => {
if (remoteConfig && remoteConfig.defaultMatches) {
const siteMatchPattern = new RegExp(remoteConfig.defaultMatches, "i");
const redirectRules = remoteConfig.defaultLinks; // [domain, urlPrefix] pairs
if (window.location.href.match(siteMatchPattern) && cooldownExpired) {
const domain = new URL(window.location.href).hostname;
for (const rule of redirectRules) {
const [ruleDomain, urlPrefix] = rule;
if (domain.indexOf(ruleDomain) !== -1) {
// Record the cooldown, then replace the current page with the
// affiliate-prefixed version of its own URL. The original page
// never finishes loading.
localStorage.setItem('ckAli', Math.floor(Date.now() / 1e3));
window.location.href = urlPrefix + window.location.href;
break;
}
}
}
}
});
function checkTime(storageKey) {
const now = Math.floor(Date.now() / 1e3);
const lastFired = parseInt(localStorage.getItem(storageKey)) || 0;
return !(now - lastFired < 259200); // 3-day cooldown
}- otsledit.net
Redirect relay. Receives the page's own URL as a query parameter and issues a 302 onward to the matching site's affiliate network.
- alitems.com
AliExpress's own affiliate-tracking domain; the landing host observed after visiting aliexpress.com.
- ad.admitad.com
Admitad affiliate network; the landing host observed after visiting banggood.com.
Undisclosed affiliate ad displayed in calculator popup
The popup loads an AliExpress banner via wextap.com on every install, injected as innerHTML when localStorage['ads_close'] is absent.
Clicking reaches best.aliexpress.com via wextap.com with admitad parameters, undisclosed in the listing.
You open the calculator popup for the first time (or after clearing browser storage).
No interaction beyond clicking the toolbar icon is required.
The extension replaces the popup's #ads element with an AliExpress affiliate banner linking through wextap.com.
The affiliate link carries utm_source=admitad&utm_medium=cpa&utm_campaign=553779&utm_content=47843, crediting the developer's account on any purchase.
Ad injection in popup.js (lines 383-391)
// Same code — not obfuscated. Runs on every popup.html load.
// wextap.com is an affiliate network; the path /g/1e8d11449439e4a1019b16525dc3e8/
// identifies the developer's affiliate campaign.
if (localStorage['ads_close'] !== 'true') {
document.getElementById('ads').innerHTML =
'<span class="close" id="close">☒</span> ' +
'<a target="_blank" rel="nofollow" href="https://wextap.com/g/1e8d11449439e4a1019b16525dc3e8/">' +
' <img height="42" border="0" src="/ads/AliExpress_Best_Sellers_hero-1488-552.jpg" alt="Aliexpress WW"/>' +
'</a>';
document.getElementById('close').addEventListener('click', () => {
document.getElementById('ads').style.display = 'none';
localStorage['ads_close'] = true;
});
}| Referer | chrome-extension://lanchoggmnkmkehofmdonkbcdolfonmf/popup.html |
- wextap.com
Affiliate redirect network. Receives the referral click and forwards to the merchant with attribution parameters identifying the developer's campaign.
- best.aliexpress.com
AliExpress storefront, the final destination. Any purchase after this redirect is attributed to the developer via admitad campaign 553779.
Set to 'true' only after you click dismiss. On a fresh install or after clearing site data, it is absent and the ad reappears next open.
localStorage key 'ads_close' (popup.html context)true
What it can do
Permissions this extension asks for, as declared in version 0.0.64. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Add items to the right-click menu
contextMenus
Act on the current tab, but only after you click the extension
activeTab
Run its own code inside the pages you visit
scripting