Is Gimp online - image editor and paint tool safe?

Medium risk

Gimp Online is medium risk. Every tab open or switch sends the page URL to offidocs.com, a third party, with a persistent per-install ID, covering all sites, not just detection pages. On by default via 'Detect files', undisclosed. Two test URLs reached it in seconds.

officeonlinesystemsv3.0.5Chrome Web Store
45Risk
Who publishes it

officeonlinesystems - 26 other listings from the same operator, 17 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
officeonlinesystems
Registered address
Av. Dr. Arce 43, Madrid 28002, Spain

Shared hosts - 1 hostname

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

offidocs.com
Also called by 7 other listings, including Image editor PaintMagick for photos, PhotoStudio, Encrypt any email with CipherMail

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Browsing History Transmitted to offidocs.com on Every Tab Visit

Every tab open or switch sends the page URL to offidocs.com, a third party, with a persistent per-install ID, covering all sites, not just detection pages.

On by default via 'Detect files', undisclosed.

Two test URLs reached it in seconds.

01EvidenceCAUSE EFFECT
Unknown block kind: cause_effect

The data has shipped a block kind this view doesn't render yet. Raw payload below.

{
  "kind": "cause_effect",
  "trigger": {
    "actor": "user",
    "summary": ""
  },
  "response": {
    "actor": "service_worker",
    "summary": ""
  }
}
02EvidenceNETWORK CAPTURE
Captured request
GEThttps://www.offidocs.com/media/system/app/checkdownloadgimp_h_z_2_nav.php?filepath=68747470733a2f2f7777772e616d617a6f6e2e636f6d2f43414e4152595f544553545f504147455f424952445f3932383337&hex=1&u=dian1sorzq
03EvidenceOPAQUE REVEAL
Why you can't catch this in DevTools

What's actually being sent
https://en.wikipedia.org/wiki/<planted marker URL>
04EvidenceCODE COMPARE
Unknown block kind: code_compare

The data has shipped a block kind this view doesn't render yet. Raw payload below.

{
  "kind": "code_compare",
  "caption": "Core transmission loop in websecure.js, tab event to outbound fetch",
  "language": "js",
  "shipped": [],
  "deobfuscated": []
}
05EvidenceFIELD TABLE
Parameters transmitted to offidocs.com on each tab navigation
FieldValueWhy it matters
68747470733a2f2f7777772e676f6f676c652e636f6dFull URL of the page just visited, hex-encoded.
1Flag telling the server the filepath is hex-encoded.
dian1sorzqPersistent 10-character random identifier tied to this browser installation.
06EvidenceTHIRD PARTY LIST
Third-party destinations
  • www.offidocs.com

    Receives every visited URL and persistent browser identifier; operator of the extension.

What it can do

Permissions this extension asks for, as declared in version 3.0.5. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Store data in your browser

    storage

  • See the address and title of every tab you have open

    tabs

Updated 30 September 2026omebobahbkampglebglkoagddjnjbhle