Is Convert HEIC to JPG safe?
Convert HEIC to JPG injects a hidden onlineapp.pro paywall iframe into every page and runs a leftover dev hot-reload client on localhost.
The extension runs a content script on every site (<all_urls>) at document load. When the toolbar icon is clicked it injects a hidden iframe from onlineapp.pro — a monetization domain separate from the product's heic-to-jpg.pro — into a shadow root on the page and lets that third-party origin open new windows via postMessage. The same content script also includes a leftover development hot-reload client that opens an unauthenticated WebSocket to ws://localhost:8081 and reloads the current tab on any 'do_update' message, which any local process bound to that port can trigger.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.