Is Calculator safe?

High risk

Calculator is high risk. Calculator's background service worker fetches a JSON configuration file from otsledit.net every time it starts, before you load any page. The file supplies the domain rules and link-rewrite prefixes used elsewhere in the extension.…

Price Trackerv0.0.64Chrome Web Store
75Risk
Who publishes it

Price Tracker - 1 other listing from the same operator, 1 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Price Tracker

Same store account

1 other listing published from this account, 20k+ users between them. 1 of them carries a finding.

Shared hosts - 2 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

otsledit.net
Also called by 2 other listings: Calculator Extension, Price tracker - Otsledit
wextap.com
Also called by 4 other listings, including Calculator Extension

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-829
SourceAI SANDBOX

Calculator fetches a remote config file that can rewrite links on any page

Calculator's background service worker fetches a JSON configuration file from otsledit.net every time it starts, before you load any page.

The file supplies the domain rules and link-rewrite prefixes used elsewhere in the extension.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You start Chrome with the Calculator extension installed.

The extension did this

The background service worker immediately requests a configuration file from otsledit.net, before any page has loaded.

The response supplies the domain-matching rules and link-rewrite prefixes used elsewhere in the extension.

02EvidenceNETWORK CAPTURE
Captured request
GEThttps://otsledit.net/calc
200 OK. 489,586-byte JSON body containing defaultMatches, defaultLinks (3,808 entries), defaultSLink and defaultMinor.
Headers
Acceptapplication/json
Content-Typeapplication/json
03EvidenceFIELD TABLE
What the returned config controls
FieldValueWhy it matters
Site matching pattern
matches include aliexpress.com, banggood.com (observed)A regular expression tested against every page you visit. Only matching pages trigger the redirect and link-rewrite logic.
Redirect destination list
["aliexpress.com", "https://otsledit.net/r?u="] (observed)3,808 domain and URL-prefix pairs. Your page's own URL gets the matching prefix glued on the front, then the browser is sent there.
Per-link rewrite rules
defaultMinor.al: [timestamp_key, link_pattern, affiliate_prefix]A separate rule list for links already on the page. Clicking a matching link briefly rewrites its destination, then restores it.
Redirect cooldown
localStorage['ckAli'], 259,200-second cooldownOnce a redirect fires on a device, a timestamp is stored so the same device is not redirected again for 3 days.
04EvidenceCODE COMPARE
The code that does this

The service worker's startup fetch and message handler

What it actually does
Annotated: the extension's own logic never decides the redirect targetsbackground.js
// State that the extension itself never populates with fixed values.
// It is entirely filled in from whatever otsledit.net returns.
let siteMatchPattern = [];   // was: defaultMatches
let redirectRules   = [];   // was: defaultLinks
let altRedirectRule = [];   // was: defaultSLink
let perLinkRules    = [];   // was: defaultMinor

// Runs on every service worker start, before any page loads.
fetch("https://otsledit.net/calc", { method: 'GET', headers: { Accept: 'application/json', 'Content-Type': 'application/json' } })
  .then(r => r.json())
  .then(remoteConfig => {
    // No local validation of remoteConfig's content beyond presence checks.
    // Whatever the server sends becomes the extension's active behavior.
    siteMatchPattern = remoteConfig.defaultMatches;
    redirectRules     = remoteConfig.defaultLinks;   // 3,808 entries observed
    altRedirectRule    = remoteConfig.defaultSLink;
    perLinkRules       = remoteConfig.defaultMinor;
  });

// content.js asks for this data via chrome.runtime.sendMessage({start:true})
// on every page load and gets back exactly what the remote server sent.
chrome.runtime.onMessage.addListener((request, sender, sendResponse) => {
  if (siteMatchPattern && redirectRules && request.start) {
    sendResponse({
      defaultMatches: siteMatchPattern,
      defaultLinks: redirectRules,
      defaultSLink: altRedirectRule,
      defaultMinor: perLinkRules
    });
  }
});
05EvidenceTHIRD PARTY LIST
Where the extension's behavior actually comes from
  • otsledit.net

    Supplies the live domain-match pattern and 3,808 redirect-prefix pairs that determine Calculator's link and page-redirect behavior. Not a resource a calculator app needs.

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Calculator redirects shopping-site visits through an affiliate link chain

When you open a shopping site matched by Calculator's remote config, such as AliExpress or Banggood, the extension replaces the page with an affiliate-prefixed version of the same URL and stores a timestamp so it does not repeat for 3 days.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You navigate to a shopping site the extension's remote config matches, such as aliexpress.com or banggood.com.

The extension did this

The content script replaces the current page with an affiliate-prefixed version of the same URL and records a 3-day cooldown.

window.location.href is set to the config's redirect prefix plus the page's own URL, so the browser navigates through the affiliate link before the original page ever renders.

02EvidenceNETWORK CAPTURE
Captured request
GEThttps://otsledit.net/r?u=https://www.aliexpress.com/
302 redirect, chained onward to alitems.com (AliExpress's own affiliate network).
03EvidenceFIELD TABLE
What we observed on two matched sites
FieldValueWhy it matters
Original page
https://www.aliexpress.com/The shopping site you actually navigated to.
Redirect prefix added
https://otsledit.net/r?u=Text placed in front of your page's URL before the browser is sent there.
Final landing host
alitems.com (from aliexpress.com); ad.admitad.com (from banggood.com)Where the redirect ends up, carrying an affiliate attribution tag for the site you were already visiting.
Cooldown marker
localStorage['ckAli']A per-device timestamp that stops the same browser from being redirected again for 3 days.
04EvidenceCODE COMPARE
The code that does this

The content script's redirect check

What it actually does
Annotatedcontent.js
// True unless a redirect already fired on this device within the last
// 259,200 seconds (3 days).
var cooldownExpired = checkTime('ckAli');

chrome.runtime.sendMessage({ start: true }, remoteConfig => {
  if (remoteConfig && remoteConfig.defaultMatches) {
    const siteMatchPattern = new RegExp(remoteConfig.defaultMatches, "i");
    const redirectRules = remoteConfig.defaultLinks; // [domain, urlPrefix] pairs

    if (window.location.href.match(siteMatchPattern) && cooldownExpired) {
      const domain = new URL(window.location.href).hostname;
      for (const rule of redirectRules) {
        const [ruleDomain, urlPrefix] = rule;
        if (domain.indexOf(ruleDomain) !== -1) {
          // Record the cooldown, then replace the current page with the
          // affiliate-prefixed version of its own URL. The original page
          // never finishes loading.
          localStorage.setItem('ckAli', Math.floor(Date.now() / 1e3));
          window.location.href = urlPrefix + window.location.href;
          break;
        }
      }
    }
  }
});

function checkTime(storageKey) {
  const now = Math.floor(Date.now() / 1e3);
  const lastFired = parseInt(localStorage.getItem(storageKey)) || 0;
  return !(now - lastFired < 259200); // 3-day cooldown
}
05EvidenceTHIRD PARTY LIST
Where the redirect ends up
  • otsledit.net

    Redirect relay. Receives the page's own URL as a query parameter and issues a 302 onward to the matching site's affiliate network.

  • alitems.com

    AliExpress's own affiliate-tracking domain; the landing host observed after visiting aliexpress.com.

  • ad.admitad.com

    Admitad affiliate network; the landing host observed after visiting banggood.com.

SeverityLOW
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Undisclosed affiliate ad displayed in calculator popup

The popup loads an AliExpress banner via wextap.com on every install, injected as innerHTML when localStorage['ads_close'] is absent.

Clicking reaches best.aliexpress.com via wextap.com with admitad parameters, undisclosed in the listing.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open the calculator popup for the first time (or after clearing browser storage).

No interaction beyond clicking the toolbar icon is required.

The extension did this

The extension replaces the popup's #ads element with an AliExpress affiliate banner linking through wextap.com.

The affiliate link carries utm_source=admitad&utm_medium=cpa&utm_campaign=553779&utm_content=47843, crediting the developer's account on any purchase.

02EvidenceCODE COMPARE
The code that does this

Ad injection in popup.js (lines 383-391)

What it actually does
// Same code — not obfuscated. Runs on every popup.html load.
// wextap.com is an affiliate network; the path /g/1e8d11449439e4a1019b16525dc3e8/
// identifies the developer's affiliate campaign.
if (localStorage['ads_close'] !== 'true') {
    document.getElementById('ads').innerHTML =
        '<span class="close" id="close">☒</span> ' +
        '<a target="_blank" rel="nofollow" href="https://wextap.com/g/1e8d11449439e4a1019b16525dc3e8/">' +
        '  <img height="42" border="0" src="/ads/AliExpress_Best_Sellers_hero-1488-552.jpg" alt="Aliexpress WW"/>' +
        '</a>';
    document.getElementById('close').addEventListener('click', () => {
        document.getElementById('ads').style.display = 'none';
        localStorage['ads_close'] = true;
    });
}
03EvidenceNETWORK CAPTURE
Captured request
GEThttps://wextap.com/g/1e8d11449439e4a1019b16525dc3e8/
302 redirect to best.aliexpress.com with query string utm_source=admitad&utm_medium=cpa&utm_campaign=553779&utm_content=47843
Headers
Refererchrome-extension://lanchoggmnkmkehofmdonkbcdolfonmf/popup.html
04EvidenceTHIRD PARTY LIST
Destinations involved in the affiliate chain
  • wextap.com

    Affiliate redirect network. Receives the referral click and forwards to the merchant with attribution parameters identifying the developer's campaign.

  • best.aliexpress.com

    AliExpress storefront, the final destination. Any purchase after this redirect is attributed to the developer via admitad campaign 553779.

05EvidenceSTORAGE DUMP
What's stored on your device

Set to 'true' only after you click dismiss. On a fresh install or after clearing site data, it is absent and the ad reappears next open.

LocationlocalStorage key 'ads_close' (popup.html context)
Contents
true

What it can do

Permissions this extension asks for, as declared in version 0.0.64. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Add items to the right-click menu

    contextMenus

  • Act on the current tab, but only after you click the extension

    activeTab

  • Run its own code inside the pages you visit

    scripting

Updated 30 September 2026lanchoggmnkmkehofmdonkbcdolfonmf