Is Video editor OpenShot online safe?

High risk

OpenShot is high risk. Dynamic analysis captured GET requests to offidocs.com on every navigation. Each visited URL, including pages unrelated to video editing, is hex-encoded and sent with a 10-char browser ID. Three navigations shared one ID in a session.…

officeonlinesystemsv2.3.6Chrome Web Store
75Risk
Who publishes it

officeonlinesystems - 26 other listings from the same operator, 17 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
officeonlinesystems
Registered address
Av. Dr. Arce 43, Madrid 28002, Spain

Shared hosts - 1 hostname

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

offidocs.com
Also called by 7 other listings, including Image editor PaintMagick for photos, PhotoStudio, Encrypt any email with CipherMail

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Every URL you visit is transmitted to offidocs.com with a persistent user ID

Dynamic analysis captured GET requests to offidocs.com on every navigation.

Each visited URL, including pages unrelated to video editing, is hex-encoded and sent with a 10-char browser ID.

Three navigations shared one ID in a session.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You navigate to any webpage not on offidocs.com.

The extension did this

The extension hex-encodes your page URL and sends it to offidocs.com via a GET request, along with a persistent 10-character ID tied to your browser.

This fires on every tab activation and every navigation update, regardless of whether you are using the extension.

02EvidenceNETWORK CAPTURE
Captured request
GEThttps://www.offidocs.com/media/system/app/checkdownloadopenshotx_2_nav.php?filepath=68747470733a2f2f7777772e676f6f676c652e636f6d2f&hex=1&u=qfyyih63ol
HTTP 200, server acknowledged receipt. When the server returns a body containing '302', the extension redirects the active tab to an offidocs.com editing URL.
03EvidenceOPAQUE REVEAL
Why you can't catch this in DevTools

The visited page URL is passed through a custom hex-encoding function (bin2hex) before being included in the query parameter. This makes the tracking destination less obvious when inspecting network traffic.

What's actually being sent
https://www.google.com/
04EvidenceFIELD TABLE
Data sent to offidocs.com on each navigation
FieldValueWhy it matters
Page URL (hex-encoded)
68747470733a2f2f7777772e616d617a6f6e2e636f6d2fThe exact address of every page you visit, encoded so it is less recognizable at a glance.
User identifier
qfyyih63olA 10-character random ID generated when the extension first runs and stored permanently, used to link all your visits together.
05EvidenceCODE COMPARE
The code that does this

Navigation listener and tracking fetch (websecure.js)

What it actually does
Tab event listeners (websecure.js lines 17-32)
function websecure() {
    this.init = function () {
        chrome.tabs.onActivated.addListener(function(activeInfo) {
                activeTabId = activeInfo.tabId;
                getTabInfo(activeTabId);
        });
        chrome.tabs.onUpdated.addListener(function(tabId, changeInfo, tab) {
                    getTabInfo(tabId);
        });
    };
}
Tracking fetch (websecure.js lines 59-109)
async function extractvideo(urlxx) {
    const offidocs_key = "offidocs_key";
    var datax = { username: null, offidocscloud: null };
    let storageResult = await chrome.storage.local.get([offidocs_key]);
    if (offidocs_key in storageResult) { datax = storageResult[offidocs_key]; }
    if (!datax.username) {
        datax.username = randomString(10);
    }
    if (!datax.offidocscloud) {
        datax.offidocscloud = "1"; // default: tracking enabled
    }
    await chrome.storage.local.set({ [offidocs_key]: datax });
    if (datax.offidocscloud == "0") return; // only skipped if user explicitly opts out
    let responsecheck = await fetch(
        'https://www.offidocs.com/media/system/app/checkdownloadopenshotx_2_nav.php?filepath='
        + bin2hex(urlxx) + '&hex=1&u=' + datax.username
    );
}
06EvidenceTHIRD PARTY LIST
Where browsing history goes
  • www.offidocs.com

    Receives the hex-encoded URL and user ID on every navigation. Operated by the developer (OffidocsGroup), which stores all tracked browsing history.

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Permanent browser identifier links all your visits at offidocs.com

Dynamic analysis confirmed the extension generates a 10-char random ID on first navigation, stores it locally, and appends it as 'u' on every request.

The same ID (qfyyih63ol) recurred across three navigations and survived a restart.

01EvidenceCAUSE EFFECT
What actually happens
You did this

The extension runs for the first time after install and processes a navigation event.

The extension did this

A permanent 10-character identifier is generated and written to local storage, where it is retrieved on every future visit and sent to offidocs.com.

Once created, the ID cannot be reset through any user-facing setting in the extension.

02EvidenceSTORAGE DUMP
What's stored on your device

'username' is your permanent tracking ID sent with every record. 'offidocscloud' controls tracking, defaults '1' (on); set '0' to stop.

Locationchrome.storage.local key 'offidocs_key'
Contents (JSON)
{
  "username": "qfyyih63ol",
  "offidocscloud": "1"
}
03EvidenceCODE COMPARE
The code that does this

User ID generation and persistence (websecure.js)

What it actually does
ID generation block (websecure.js lines 59-88)
async function extractvideo(urlxx) {
    const STORAGE_KEY = "offidocs_key";
    // Load existing tracking state from local storage
    let storageResult = await chrome.storage.local.get([STORAGE_KEY]);
    let trackingData = (STORAGE_KEY in storageResult)
        ? storageResult[STORAGE_KEY]
        : { username: null, offidocscloud: null };

    // Generate a permanent user ID if one doesn't exist yet
    if (!trackingData.username) {
        trackingData.username = randomString(10).toLowerCase();
    }

    // Default tracking to enabled ('1'); user must explicitly set '0' to stop
    if (!trackingData.offidocscloud) {
        trackingData.offidocscloud = "1";
    }

    // Persist to local storage — survives browser restarts
    await chrome.storage.local.set({ [STORAGE_KEY]: trackingData });
}
04EvidenceFIELD TABLE
What the persistent identifier enables
FieldValueWhy it matters
Tracking ID
qfyyih63olA unique token stored in your browser that lets offidocs.com link all your page visits to one profile across separate sessions.
Browsing history linkage
https://www.amazon.com/ → 68747470733a2f2f7777772e616d617a6f6e2e636f6d2fEvery URL sent to offidocs.com is tagged with this ID, building a persistent server-side log of your browsing activity tied to your browser.

What it can do

Permissions this extension asks for, as declared in version 2.3.6. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Store data in your browser

    storage

  • See the address and title of every tab you have open

    tabs

Updated 30 September 2026kdfinbdncekfhibpbnkjedmdofkjghjj