Is Legrooms+ for Google Flights safe?

Medium risk

legrooms+-for-google-flig is medium risk. Legrooms+ bundles Vio.com's Hermes tracker, active on 37 hotel-site patterns regardless of extension use. It sent the hotel page's domain, type, and listing name to a Vio endpoint with an affiliate ID; a coded price endpoint didn't fire.

45Risk
Who publishes it

No other listings under this identity, 10 shared hostnames

What this publisher told the store about itself, and the other listings that told it the same thing.

Shared hosts - 10 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

cdn.travelarrow.io
Also called by 1 other listing: TripChipper
help.marriott.com
Also called by 1 other listing: TripChipper
hotels.travelarrow.io
Also called by 1 other listing: TripChipper
roomunlocker.com
Also called by 1 other listing: TripChipper
seatmaps.com
Also called by 1 other listing
api.travelarrow.io
Also called by 2 other listings
carsandstays.delta
Also called by 3 other listings, including Karma
choicehotels.com
Also called by 3 other listings, including Guestbook Extension
travelarrow.io
Also called by 3 other listings, including Airbnb for Digital Nomads
vacations.alaskaair
Also called by 3 other listings, including Karma

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Hotel Search Pages You Visit Are Reported to Vio's Ad Network

Legrooms+ bundles Vio.com's Hermes tracker, active on 37 hotel-site patterns regardless of extension use.

It sent the hotel page's domain, type, and listing name to a Vio endpoint with an affiliate ID; a coded price endpoint didn't fire.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You browse to a supported hotel or travel site, such as Booking.com, in any open tab.

Legrooms+ doesn't need to be actively used for its flight-seat feature; the tracking module runs in the background on a matched page.

The extension did this

The bundled Vio Hermes tracking module reports the page you're viewing to a Vio.com analytics endpoint.

It sends the site name, the page type, and the name of the specific hotel listing you opened, tagged with the Legrooms+ affiliate ID.

02EvidenceNETWORK CAPTURE
Captured request
POSThttps://fe-evas.fih.io/browser-extension/event
200 OK, observed during dynamic analysis while browsing Booking.com search-results and a hotel-listing page; four such requests fired across the two pages.
Headers
accept*/*
x-api-key<redacted>
content-typeapplication/json
Body
{
  "properties": {
    "category": "System",
    "entity": "TargetedPage",
    "action": "Displayed",
    "analyticsContext": {
      "pageContext": {
        "pageDomain": "booking",
        "pageType": "searchResults"
      }
    },
    "bookingContext": {
      "firstHotelName": "Beautiful 3 bedroom apartments in Shoreditch"
    },
    "payload": {
      "anonymousId": "b3f2a9de-7c41-4e88-9a2f-114fbb2ad013",
      "affiliateName": "legrooms",
      "sdkVersion": "1.3.2"
    },
    "anonymousId": "b3f2a9de-7c41-4e88-9a2f-114fbb2ad013",
    "name": "System_TargetedPage_Displayed"
  }
}
03EvidenceFIELD TABLE
What Hermes reports about the page you're on
FieldValueWhy it matters
Site you're browsing
bookingIdentifies which travel or hotel-booking site you're currently on.
Page type
searchResultsTells Vio whether you're viewing search results, a hotel listing, or another page type on the site.
Hotel you're viewing
Beautiful 3 bedroom apartments in ShoreditchThe name of the specific hotel listing shown on the page, reveals exactly which property you're considering.
Per-install ID
b3f2a9de-7c41-4e88-9a2f-114fbb2ad013 (illustrative)A persistent random ID tied to your extension install, letting Vio link every hotel page you visit into one profile over time.
Referring extension
legroomsIdentifies Legrooms+ as the source of the visit so Vio can attribute the referral and pay a commission on the partner's behalf.
04EvidenceCODE COMPARE
The code that does this

Hermes SDK: endpoint config, the site-matcher list, and the tracking call

What it actually does
Endpoint configvio.js
const n = {
  apiBaseUrl: "https://partners.api.vio.com/v1",
  trackingUrl: "https://fe-evas.fih.io/browser-extension/event",
  remoteConfigUrl: "https://www.vio.com/js/browser-extension/remote-config/v1/config.json",
  apiKey: "",
  trackingKey: String("<redacted>"),
  version: "1.3.2",
  options: {
    debug: false,
    verboseLogging: false,
    language: "en-US",
    fetcher: (...e) => fetch(...e),
    storage: typeof chrome !== "undefined" && chrome.storage !== undefined ? chrome.storage : {
      sync: {
        get: async () => Promise.resolve({}),
        set: async () => Promise.resolve(),
        remove: async () => Promise.resolve(),
        clear: async () => Promise.resolve()
      },
      local: {
        get: async () => Promise.resolve({}),
        set: async () => Promise.resolve(),
        remove: async () => Promise.resolve(),
        clear: async () => Promise.resolve()
      }
    }
  },
  update(e) {
    Object.assign(this, e)
  }
}
Site-matcher list (37 patterns)vio.js
getAppConfigByKey("hermes_matcher_regexes", [{
  regex: "https://.*tripadvisor.*",
  flags: ""
}, {
  regex: "https://.*kayak.*",
  flags: ""
}, {
  regex: "https://.*expedia.*",
  flags: ""
}, {
  regex: "https://.*booking.*",
  flags: ""
}, {
  regex: "https://.*hotel.*",
  flags: ""
}, {
  regex: "https://.*hoteles.*",
  flags: ""
}, {
  regex: "https://.*tripadvisor.*",
  flags: ""
}, {
  regex: "https://.*expedia-aarp.*",
  flags: ""
}, {
  regex: "https://.*expediataap.*",
  flags: ""
}, {
  regex: "https://.*travelocity.*",
  flags: ""
}, {
  regex: "https://.*orbitz.*",
  flags: ""
}, {
  regex: "https://.*cheaptickets.*",
  flags: ""
}, {
  regex: "https://.*ebookers.*",
  flags: ""
}, {
  regex: "https://.*wotif.*",
  flags: ""
}, {
  regex: "https://.*lastminute.*",
  flags: ""
}, {
  regex: "https://carsandstays.delta.*",
  flags: ""
}, {
  regex: "https://vacations.alaskaair.*",
  flags: ""
}, {
  regex: "https://*.priceline.com",
  flags: ""
}, {
  regex: "https://*.marriott.*",
  flags: ""
}, {
  regex: "https://.*hilton.*/en/book/reservation.*",
  flags: ""
}, {
  regex: "https://.*hilton.*/en/search.*",
  flags: ""
}, {
  regex: "https://.*accor.*",
  flags: ""
}, {
  regex: "https://.*agoda.*",
  flags: ""
}, {
  regex: "https://.*caesars.*/book/(.*/hotel.*|room-list.*)",
  flags: ""
}, {
  regex: "https://.*caesars.*/book/(search|hotel-list.*)",
  flags: ""
}, {
  regex: "https://.*choicehotels.*/(reservations/.*|.*-hotels/.*)",
  flags: ""
}, {
  regex: "https://.*choicehotels.*/(reservations/hotel-list.*|regional-hotels.*)",
  flags: ""
}, {
  regex: "https://.*hyatt.*/shop/.*",
  flags: ""
}, {
  regex: "https://.*hyatt.*/(explore-hotels/map.*|search/hotels/.*)",
  flags: ""
}, {
  regex: "https://.*ihg.*/hotels/.*/(hoteldetail.*|find-hotels/select-roomrate.*)",
  flags: ""
}, {
  regex: "https://.*ihg.*/hotels/.*/(reservation.*|find-hotels/hotel-search.*)",
  flags: ""
}, {
  regex: "https://.*mgmresorts.*/(en/hotels/.*|book-room/room/.*)",
  flags: ""
}, {
  regex: "https://.*mgmresorts.*/(en/hotels.html.*|book-room/resort/.*)",
  flags: ""
}, {
  regex: "https://.*trip.com/hotels/detail.*",
  flags: ""
}, {
  regex: "https://.*trip.com/hotels/list.*",
  flags: ""
}, {
  regex: "https://.*wyndhamhotels.*/(wyndham/.*|.*/rooms-rates.*)",
  flags: ""
}, {
  regex: "https://.*wyndhamhotels.*/(hotel-search.*|hotels/.*)",
  flags: ""
}])
track() — builds and sends the eventvio.js
async track(e) {
  const t = [e.category, e.entity, e.action].filter(Boolean).join("_");
  return n.options.fetcher(n.trackingUrl, {
    headers: {
      accept: "*/*",
      "content-type": "application/json",
      "x-api-key": n.trackingKey
    },
    method: "POST",
    body: JSON.stringify({
      properties: {
        ...e,
        anonymousId: this.anonymousId,
        name: t
      }
    })
  })
}
05EvidenceTHIRD PARTY LIST
Where the tracking data goes
  • fe-evas.fih.io

    Vio.com's tracking-event ingestion endpoint. Receives the page/hotel context payload shown above, tagged with the Legrooms+ affiliate ID, confirmed by traffic capture.

  • partners.api.vio.com

    Vio.com's hotel-search API. The SDK is coded to POST check-in/checkout dates, guest counts, and prices here on a matched page; it did not fire in our test.

  • www.vio.com

    Serves the remote config that lists which site URL patterns trigger tracking (hermes_matcher_regexes), Vio can change the matched-site list without an extension update.

Updated 30 September 2026nhonfddkgankhjilponlbdccpabaaknp