Is DocsWork Editor for documents DOC & DOCX safe?

High risk

DocsWork is high risk. DocsWork Editor sends visited page URLs to stream.redcoolmedia.net/api/docworku-h.php when tabs open or activate. The URL is hex-encoded, plus the same 10-character user ID each time, building a browsing-history stream.…

RedcoolMediav1.4.4Chrome Web Store
75Risk
Who publishes it

RedcoolMedia - 15 other listings from the same operator, 10 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
RedcoolMedia
Registered address
Europe Avenue, S/N, Pozuelo 28224, Spain

Same store account

15 other listings published from this account, 422k+ users between them. 10 of them carry a finding.

Shared hosts - 2 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

stream.redcoolmedia.net
Also called by 4 other listings
redcoolmedia.net
Also called by 8 other listings

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Browsing history sent to Redcoolmedia on navigation

DocsWork Editor sends visited page URLs to stream.redcoolmedia.net/api/docworku-h.php when tabs open or activate.

The URL is hex-encoded, plus the same 10-character user ID each time, building a browsing-history stream.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open a page or activate a browser tab.

The extension did this

The extension sends that page address to Redcoolmedia with a stable user identifier.

02EvidenceNETWORK CAPTURE
Captured request
GEThttps://stream.redcoolmedia.net/api/docworku-h.php?l=68747470733a2f2f7777772e676f6f676c652e636f6d2f&hex=1&u=scac5yvkde
A second observed GET to the same endpoint used the same u=scac5yvkde identifier with a different encoded visited URL.
03EvidenceOPAQUE REVEAL
Why you can't catch this in DevTools

The visited URL is not sent as readable text; it is hex-encoded in the query string.

What's actually being sent
https://www.google.com/
04EvidenceFIELD TABLE
Fields sent to stream.redcoolmedia.net
FieldValueWhy it matters
Visited page URL
https://www.google.com/Shows the exact page you opened in the active tab.
Browsing sequence
https://www.google.com/ followed by another observed page visitRepeated requests let the service build a timeline of pages you visit.
Extension user ID
scac5yvkdeLets separate page visits be linked back to the same browser profile.
05EvidenceCODE COMPARE
The code that does this

Tab events feed the URL sender

What it actually does
Readable equivalent of the shipped service worker importdeobfuscated/service.js
importScripts(
    "./web.js"
);
Readable equivalent of the tab listener and URL filterdeobfuscated/web.js
function xdii(tabId) {
      chrome.tabs.get(tabId, function(tab) {          
            if ( ( tab.url.indexOf("redco") == -1 ) && ( tab.url.indexOf("http") !== -1 ) && ( lasiee != tab.url) )  {
                    utyu =  tab.url;
                    rtcc = "";
                    rtcc =   utyu;  
                    exx(rtcc);
                    lasiee = tab.url;
            }
      });
}


function web() {
    this.init = function () {
        
        chrome.tabs.onActivated.addListener(function(activeInfo) {
                aati = activeInfo.tabId;
                xdii(aati);
        });

        chrome.tabs.onUpdated.addListener(function(tabId, changeInfo, tab) {
                    xdii(tabId);
        });
     
    };
}
Readable equivalent of the request construction and URL encoderdeobfuscated/web.js
async function exx(urly) {
    
    
    var redxda = { usernameredcool: null,  redcoolonline: null };
    var usernameredcool = "";
    var redcoolonline = "";
    const redcool_key = "redcool_key";

    let storageResult = await chrome.storage.local.get([redcool_key]);

    if (redcool_key in storageResult) {
            redxda = storageResult[redcool_key]
    }

    if ( redxda.usernameredcool ) {
        usernameredcool = redxda.usernameredcool;
    }
    else {
        usernameredcool = "" + randomString(10) + "".toLowerCase();
        redxda.usernameredcool = usernameredcool;
    }

    if ( redxda.redcoolonline ) {
        redcoolonline = redxda.redcoolonline;
    }
    else {
        redcoolonline = "1";
        redxda.redcoolonline = "1";
    }

    var stox = {};
    stox[redcool_key] = redxda;
    await chrome.storage.local.set(stox);
    
    var date = new Date();
                
    var un = usernameredcool;
    
    if ( redxda.redcoolonline == "0") 
        return;
    
        
     let rtcx = await fetch('https://stream.redcoolmedia.net/api/docworku-h.php?l=' + bin2hex(urly) + '&hex=1&u=' + un);
                    
     if (rtcx.status === 200) {
              let dsx = await rtcx.text();
              console.log(dsx);  
              var rse2 = dsx;
              if ( rse2.indexOf("302") !== -1 )   {
                       var cvcv = 'https://www.redcoolmedia.net/api/app-docwork.php?url=' + bin2hex(urly) + '&u=' + un;
                       //chrome.tabs.create({ url: cvcv });
                       chrome.tabs.update(chrome.tabs.getCurrent().id, {url: cvcv});
             }
                                  
     }   
    
    
                
    
}


function bin2hex (bin)
{
  var i = 0, l = bin.length, chr, hex = '';
  for (i; i < l; ++i)
  {
    chr = bin.charCodeAt(i).toString(16)
    hex += chr.length < 2 ? '0' + chr : chr
  }
  return hex
}
06EvidenceTHIRD PARTY LIST
Remote services contacted for this behavior
  • stream.redcoolmedia.net

    Receives the encoded visited URL and extension user identifier at /api/docworku-h.php.

  • www.redcoolmedia.net

    Used by the same code path as a follow-up redirect target when the response text contains 302.

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Browsing-history collection enabled on first install

DocsWork Editor sends the first visited page to stream.redcoolmedia.net/api/docworku-h.php right after install, before the popup opens or consent is used.

Local collection defaults to enabled; opt-out exists only inside the popup.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You install the extension and open a web page.

The extension did this

The extension treats browsing-history collection as enabled and sends the page address before you use the popup control.

02EvidenceNETWORK CAPTURE
Captured request
GEThttps://stream.redcoolmedia.net/api/docworku-h.php?l=68747470733a2f2f7777772e676f6f676c652e636f6d2f&hex=1&u=scac5yvkde
Observed as the first request to the tracking endpoint after install, before the extension popup was opened or any consent control was used.
03EvidenceFIELD TABLE
Values involved in the first request
FieldValueWhy it matters
First visited URL
https://www.google.com/Shows the page you opened immediately after installing the extension.
Collection setting
EnabledThe extension stores collection as enabled unless you later change it in the popup.
Extension user ID
scac5yvkdeLinks the first page visit to the same browser profile used in later requests.
04EvidenceCODE COMPARE
The code that does this

Missing preference becomes enabled before any opt-out

What it actually does
Readable equivalent of the service worker sender defaultdeobfuscated/web.js
async function exx(urly) {
    
    
    var redxda = { usernameredcool: null,  redcoolonline: null };
    var usernameredcool = "";
    var redcoolonline = "";
    const redcool_key = "redcool_key";

    let storageResult = await chrome.storage.local.get([redcool_key]);

    if (redcool_key in storageResult) {
            redxda = storageResult[redcool_key]
    }

    if ( redxda.usernameredcool ) {
        usernameredcool = redxda.usernameredcool;
    }
    else {
        usernameredcool = "" + randomString(10) + "".toLowerCase();
        redxda.usernameredcool = usernameredcool;
    }

    if ( redxda.redcoolonline ) {
        redcoolonline = redxda.redcoolonline;
    }
    else {
        redcoolonline = "1";
        redxda.redcoolonline = "1";
    }

    var stox = {};
    stox[redcool_key] = redxda;
    await chrome.storage.local.set(stox);
    
    var date = new Date();
                
    var un = usernameredcool;
    
    if ( redxda.redcoolonline == "0") 
        return;
    
        
     let rtcx = await fetch('https://stream.redcoolmedia.net/api/docworku-h.php?l=' + bin2hex(urly) + '&hex=1&u=' + un);
                    
     if (rtcx.status === 200) {
              let dsx = await rtcx.text();
              console.log(dsx);  
              var rse2 = dsx;
              if ( rse2.indexOf("302") !== -1 )   {
                       var cvcv = 'https://www.redcoolmedia.net/api/app-docwork.php?url=' + bin2hex(urly) + '&u=' + un;
                       //chrome.tabs.create({ url: cvcv });
                       chrome.tabs.update(chrome.tabs.getCurrent().id, {url: cvcv});
             }
                                  
     }   
    
    
                
    
}
Readable equivalent of the popup default and checkbox handlerdeobfuscated/apar.js
var redxda = { usernameredcool: null,  redcoolonline: null };

const redcool_key = "redcool_key";
var redcoolonline = "";

let storageResult = await chrome.storage.local.get([redcool_key]);

if (redcool_key in storageResult) {
        redxda = storageResult[redcool_key]
}

if ( redxda.usernameredcool ) {
    usernameredcool = redxda.usernameredcool;
}
else {
    usernameredcool = "" + randomString(10) + "".toLowerCase();
    redxda.usernameredcool = usernameredcool;
}

if ( redxda.redcoolonline ) {
    redcoolonline = redxda.redcoolonline;
}
else {
    redcoolonline = "1";
    redxda.redcoolonline = "1";
}

var stox = {};
stox[redcool_key] = redxda;
await chrome.storage.local.set(stox);

if ( redcoolonline == "1")  {
    document.getElementById("redcoolonline").checked = true;
}
else {
    document.getElementById("redcoolonline").checked = false;
}

$("#redcoolonline").click(async function() {
    if (document.getElementById('redcoolonline').checked) {
        redxda.usernameredcool = usernameredcool;
        redxda.redcoolonline = "1";    
        var stox = {};
        stox[redcool_key] = redxda;
        await chrome.storage.local.set(stox);
    }
    else {
        redxda.usernameredcool = usernameredcool;
        redxda.redcoolonline = "0";    
        var stox = {};
        stox[redcool_key] = redxda;
        await chrome.storage.local.set(stox);
    }
    return false;
});
Readable equivalent of the popup consent text and checkboxdeobfuscated/index.html
<span class="label" style="color: #000000">
  <input type="checkbox" id="redcoolonline" style="width: 20px; float: left;" /> 
                  Scan Online
              </span>

<div style="margin-left: 5px; padding-bottom: 5px;  width: 100%;   padding-top: 5px; font-size: 14px; color: #333333; ">NOTE: Please note that this extension scans and collects the webpages you browse in the Internet. These webpages are uploaded to our servers in order to know if they contain Office files that can be edited using our extension. Refer to our policy about it.</div>
05EvidenceSTORAGE DUMP
What's stored on your device

This local record links the browser profile to requests and stores collection as enabled until the popup checkbox changes it.

Locationchrome.storage.local key redcool_key
Contents (JSON)
{
  "redcoolonline": "1",
  "usernameredcool": "scac5yvkde"
}
SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Popup Fetches Stored Browsing History

Opening the popup loads a stored Redcoolmedia user ID and requests prior browsing entries from stream.redcoolmedia.net when Scan Online is on, rendering each as a link.

No popup was opened during capture, so no response was recorded.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open the extension popup.

The popup contains a Scan Online switch that defaults to enabled when no stored setting exists.

The extension did this

The popup asks Redcoolmedia for browsing entries tied to the stored user ID.

Returned entries are parsed into clickable links inside the popup.

02EvidenceNETWORK CAPTURE
Captured request
GEThttps://stream.redcoolmedia.net/api/docworkb-h.php?u=a8k2m9q1xz
No response body was recorded because the popup was not opened during traffic capture.
03EvidenceFIELD TABLE
Fields used by the popup history request and parser
FieldValueWhy it matters
Your Redcoolmedia user ID
a8k2m9q1xz (illustrative)This ties the returned browsing list to the same browser profile across popup opens.
Visited page URL
https://docs.example.org/team/roadmap.html (illustrative)This reveals the exact page that appears in the popup's browsing-history list.
Page title or label
Team Roadmap Q3 (illustrative)This adds readable context to the URL, making the visited page easier to recognize.
Response delimiters
XXXXXhttps://docs.example.org/team/roadmap.htmlYYYYYTeam Roadmap Q3ZZZZZ (illustrative)These fixed markers show how the popup separates each returned URL from its displayed title.
04EvidenceCODE COMPARE
The code that does this

Popup wiring and history retrieval code

What it actually does
The extension button opens index.htmldeobfuscated/manifest.json
{
  "action": {
    "default_popup": "index.html",
    "default_icon": "icons/app_38.png"
  }
}
index.html loads apar.js and contains the history listdeobfuscated/index.html
<head>
        <meta charset="UTF-8">
        <title>DocsWork doc editor</title>
        <link href="popup.css" rel="stylesheet" type="text/css">
        <script src="jquery.min.js"></script>
        <script src="apar.js"></script>
        <link href="styles.css" rel="stylesheet" type="text/css" />
</head>

<div class="pn-Redcoolmedia" style="margin-top: 0px; background: #0A8CC8; color: #fff; padding-left: 10px;  padding-top: 5px; padding-bottom: 5px; padding-right: 10px; font-size: 17px; float: left; width: 100%;">
<p style="margin: 0;">* URLs navigated to scan for files to edit with DocsWork:</p>
</div>

<div id="urlbrowsed" style="margin-top: 0px; background: #ffffff; color: #fff; padding-left: 10px;  padding-top: 5px; padding-bottom: 5px; padding-right: 10px; font-size: 13px; float: left; width: 100%; height: 100px; overflow-y: scroll;">
</div>
apar.js requests stored history and renders returned linksdeobfuscated/apar.js
urlbrowsed = document.getElementById('urlbrowsed');  
urlbrowsed.innerHTML = "";
var aa = 0;
var xhrbb = new XMLHttpRequest();
xhrbb.open('GET', 'https://stream.redcoolmedia.net/api/docworkb-h.php?u=' + usernameredcool, true);
xhrbb.onload = function (e) {
                if (xhrbb.readyState === 4) {
                        if (xhrbb.status === 200) {
                                //console.log(xhrbb);
                                var response1 = xhrbb.responseText;
                                loqueda = response1;
                
                                while ( loqueda.indexOf('XXXXX') != -1 ) 
                                {
                                    var part1 = loqueda.substring(
                                        loqueda.indexOf("XXXXX"), 
                                        loqueda.indexOf("ZZZZZ") + 5
                                    );

                                    var pathx = part1.substring(
                                        part1.indexOf("XXXXX") + 5, 
                                        part1.indexOf("YYYYY")
                                    );

                                    var namex = "- Click to scan for files in the URL " + part1.substring(
                                        part1.indexOf("YYYYY") + 5, 
                                        part1.indexOf("ZZZZZ")
                                    );


                                    var $link = $('<a>').text(namex).on("click", function(){ detectfilesperurl(this.id); });
                                    $link.attr('id', pathx);
                                    //$link.attr('hex', pathx);
                                    
                                     $("#urlbrowsed").append($link);
                                     $("#urlbrowsed").append("<br>");
                                    loqueda = loqueda.replace(part1, "");
                                }

                         } else {
                                urlbrowsed = document.getElementById('urlbrowsed');  
                                urlbrowsed.innerHTML = "<p style='color: #000000;'>No URLs browsed yet</p>";
                        }
                 }
        };
xhrbb.onerror = function (e) {
                urlbrowsed = document.getElementById('urlbrowsed');  
                urlbrowsed.innerHTML = "<p style='color: #000000;'>No URLs browsed yet</p>";
};

if ( redcoolonline == "1")  {
     xhrbb.send();
}
else {
    urlbrowsed = document.getElementById('urlbrowsed');  
    urlbrowsed.innerHTML = "<p style='color: #000000;'>Scan disabled</p>";
}
05EvidenceTHIRD PARTY LIST
External host used by the popup history feature
  • stream.redcoolmedia.net

    Receives the popup's user ID query and returns the browsing-history entries consumed by the popup parser.

What it can do

Permissions this extension asks for, as declared in version 1.4.4. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Store data in your browser

    storage

  • See the address and title of every tab you have open

    tabs

Updated 30 September 2026gnmngcgmijhkamopfhmnkgpebgjbpbja