Is Legrooms+ for Google Flights safe?
legrooms+-for-google-flig is medium risk. Legrooms+ bundles Vio.com's Hermes tracker, active on 37 hotel-site patterns regardless of extension use. It sent the hotel page's domain, type, and listing name to a Vio endpoint with an affiliate ID; a coded price endpoint didn't fire.
Who publishes itNo other listings under this identity, 10 shared hostnames
No other listings under this identity, 10 shared hostnames
What this publisher told the store about itself, and the other listings that told it the same thing.
Shared hosts - 10 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Hotel Search Pages You Visit Are Reported to Vio's Ad Network
Legrooms+ bundles Vio.com's Hermes tracker, active on 37 hotel-site patterns regardless of extension use.
It sent the hotel page's domain, type, and listing name to a Vio endpoint with an affiliate ID; a coded price endpoint didn't fire.
You browse to a supported hotel or travel site, such as Booking.com, in any open tab.
Legrooms+ doesn't need to be actively used for its flight-seat feature; the tracking module runs in the background on a matched page.
The bundled Vio Hermes tracking module reports the page you're viewing to a Vio.com analytics endpoint.
It sends the site name, the page type, and the name of the specific hotel listing you opened, tagged with the Legrooms+ affiliate ID.
| accept | */* |
| x-api-key | <redacted> |
| content-type | application/json |
{
"properties": {
"category": "System",
"entity": "TargetedPage",
"action": "Displayed",
"analyticsContext": {
"pageContext": {
"pageDomain": "booking",
"pageType": "searchResults"
}
},
"bookingContext": {
"firstHotelName": "Beautiful 3 bedroom apartments in Shoreditch"
},
"payload": {
"anonymousId": "b3f2a9de-7c41-4e88-9a2f-114fbb2ad013",
"affiliateName": "legrooms",
"sdkVersion": "1.3.2"
},
"anonymousId": "b3f2a9de-7c41-4e88-9a2f-114fbb2ad013",
"name": "System_TargetedPage_Displayed"
}
}| Field | Value | Why it matters | |
|---|---|---|---|
Site you're browsing | booking | Identifies which travel or hotel-booking site you're currently on. | |
Page type | searchResults | Tells Vio whether you're viewing search results, a hotel listing, or another page type on the site. | |
Hotel you're viewing | Beautiful 3 bedroom apartments in Shoreditch | The name of the specific hotel listing shown on the page, reveals exactly which property you're considering. | |
Per-install ID | b3f2a9de-7c41-4e88-9a2f-114fbb2ad013 (illustrative) | A persistent random ID tied to your extension install, letting Vio link every hotel page you visit into one profile over time. | |
Referring extension | legrooms | Identifies Legrooms+ as the source of the visit so Vio can attribute the referral and pay a commission on the partner's behalf. |
Hermes SDK: endpoint config, the site-matcher list, and the tracking call
const n = {
apiBaseUrl: "https://partners.api.vio.com/v1",
trackingUrl: "https://fe-evas.fih.io/browser-extension/event",
remoteConfigUrl: "https://www.vio.com/js/browser-extension/remote-config/v1/config.json",
apiKey: "",
trackingKey: String("<redacted>"),
version: "1.3.2",
options: {
debug: false,
verboseLogging: false,
language: "en-US",
fetcher: (...e) => fetch(...e),
storage: typeof chrome !== "undefined" && chrome.storage !== undefined ? chrome.storage : {
sync: {
get: async () => Promise.resolve({}),
set: async () => Promise.resolve(),
remove: async () => Promise.resolve(),
clear: async () => Promise.resolve()
},
local: {
get: async () => Promise.resolve({}),
set: async () => Promise.resolve(),
remove: async () => Promise.resolve(),
clear: async () => Promise.resolve()
}
}
},
update(e) {
Object.assign(this, e)
}
}getAppConfigByKey("hermes_matcher_regexes", [{
regex: "https://.*tripadvisor.*",
flags: ""
}, {
regex: "https://.*kayak.*",
flags: ""
}, {
regex: "https://.*expedia.*",
flags: ""
}, {
regex: "https://.*booking.*",
flags: ""
}, {
regex: "https://.*hotel.*",
flags: ""
}, {
regex: "https://.*hoteles.*",
flags: ""
}, {
regex: "https://.*tripadvisor.*",
flags: ""
}, {
regex: "https://.*expedia-aarp.*",
flags: ""
}, {
regex: "https://.*expediataap.*",
flags: ""
}, {
regex: "https://.*travelocity.*",
flags: ""
}, {
regex: "https://.*orbitz.*",
flags: ""
}, {
regex: "https://.*cheaptickets.*",
flags: ""
}, {
regex: "https://.*ebookers.*",
flags: ""
}, {
regex: "https://.*wotif.*",
flags: ""
}, {
regex: "https://.*lastminute.*",
flags: ""
}, {
regex: "https://carsandstays.delta.*",
flags: ""
}, {
regex: "https://vacations.alaskaair.*",
flags: ""
}, {
regex: "https://*.priceline.com",
flags: ""
}, {
regex: "https://*.marriott.*",
flags: ""
}, {
regex: "https://.*hilton.*/en/book/reservation.*",
flags: ""
}, {
regex: "https://.*hilton.*/en/search.*",
flags: ""
}, {
regex: "https://.*accor.*",
flags: ""
}, {
regex: "https://.*agoda.*",
flags: ""
}, {
regex: "https://.*caesars.*/book/(.*/hotel.*|room-list.*)",
flags: ""
}, {
regex: "https://.*caesars.*/book/(search|hotel-list.*)",
flags: ""
}, {
regex: "https://.*choicehotels.*/(reservations/.*|.*-hotels/.*)",
flags: ""
}, {
regex: "https://.*choicehotels.*/(reservations/hotel-list.*|regional-hotels.*)",
flags: ""
}, {
regex: "https://.*hyatt.*/shop/.*",
flags: ""
}, {
regex: "https://.*hyatt.*/(explore-hotels/map.*|search/hotels/.*)",
flags: ""
}, {
regex: "https://.*ihg.*/hotels/.*/(hoteldetail.*|find-hotels/select-roomrate.*)",
flags: ""
}, {
regex: "https://.*ihg.*/hotels/.*/(reservation.*|find-hotels/hotel-search.*)",
flags: ""
}, {
regex: "https://.*mgmresorts.*/(en/hotels/.*|book-room/room/.*)",
flags: ""
}, {
regex: "https://.*mgmresorts.*/(en/hotels.html.*|book-room/resort/.*)",
flags: ""
}, {
regex: "https://.*trip.com/hotels/detail.*",
flags: ""
}, {
regex: "https://.*trip.com/hotels/list.*",
flags: ""
}, {
regex: "https://.*wyndhamhotels.*/(wyndham/.*|.*/rooms-rates.*)",
flags: ""
}, {
regex: "https://.*wyndhamhotels.*/(hotel-search.*|hotels/.*)",
flags: ""
}])async track(e) {
const t = [e.category, e.entity, e.action].filter(Boolean).join("_");
return n.options.fetcher(n.trackingUrl, {
headers: {
accept: "*/*",
"content-type": "application/json",
"x-api-key": n.trackingKey
},
method: "POST",
body: JSON.stringify({
properties: {
...e,
anonymousId: this.anonymousId,
name: t
}
})
})
}- fe-evas.fih.io
Vio.com's tracking-event ingestion endpoint. Receives the page/hotel context payload shown above, tagged with the Legrooms+ affiliate ID, confirmed by traffic capture.
- partners.api.vio.com
Vio.com's hotel-search API. The SDK is coded to POST check-in/checkout dates, guest counts, and prices here on a matched page; it did not fire in our test.
- www.vio.com
Serves the remote config that lists which site URL patterns trigger tracking (hermes_matcher_regexes), Vio can change the matched-site list without an extension update.