Is Right Click Enable safe?
Right Click Enable is medium risk. Reporting a problem through the feedback popup and confirming the prompt makes Right Click Enable include the page URL in the feedback payload, posted to clevermathgames.com. DA didn't trigger this; details come from the shipped code.…
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Feedback sends the current page URL to clevermathgames.com
Reporting a problem through the feedback popup and confirming the prompt makes Right Click Enable include the page URL in the feedback payload, posted to clevermathgames.com.
DA didn't trigger this; details come from the shipped code.
You report that the extension did not work on the current page.
The popup asks you to choose a content type and a specific problem before showing a confirmation dialog.
The extension prepares a feedback request that includes the full current page URL.
If you confirm, it posts the JSON feedback request to clevermathgames.com.
| Field | Value | Why it matters | |
|---|---|---|---|
Extension name | Right Click Enable | Identifies which extension generated the report. | |
Current page URL | https://accounts.example.com/settings/security | Shows the exact page you had open when you submitted feedback. | |
Extension version | 0.7.7 | Ties the feedback report to the installed extension build. | |
Issue type | text | Records the category you selected in the feedback popup. | |
Issue description | Cannot copy text | Records the specific problem button you clicked. |
| Content-Type | application/json |
The feedback path reads the page URL and posts it
function promptSpecificFeedback(type){const feedbackTypes={text:{question:"What problem occurs with the text?",options:["Text cannot be selected","Menu does not appear","Cannot copy text","Another problem"]},image:{question:"What problem occurs with the image?",options:["Menu does not appear","Cannot save image as","Cannot copy image to clipboard","Another problem"]},video:{question:"What problem occurs with the video?",options:["Menu does not appear","Cannot save video as","Cannot save video frame as","Cannot copy video frame to clipboard","Another problem"]}};const{question,options}=feedbackTypes[type];feedbackPopup.innerHTML=`
<button id="close-button">×</button>
<h3>${question}</h3>
${options.map((option, index) => `<button class="problem-button"data-issue="${option}">${option}</button>`).join('')}
`;shadowRoot.getElementById('close-button').onclick=cleanupPopup;Array.from(shadowRoot.querySelectorAll('.problem-button')).forEach(button=>{button.onclick=()=>submitFeedback(type,button.getAttribute('data-issue'));});}function submitFeedback(issueType,issueDescription){const currentUrl=currentLocation.href;const dataToSend=`Extension: ${extensionName} v${extensionVersion}\nURL: ${currentUrl}\nProblem: ${issueDescription}`;const userConfirmed=window.confirm(`This feedback will be sent to developers:\n\n${dataToSend}\n\n`+"Ensure no sensitive data is included.\n\n"+"Continue sending?");if(userConfirmed){const data={name:extensionName,URL:currentUrl,version:extensionVersion,issueType:issueType,issueDescription:issueDescription};fetch('https://clevermathgames.com/wp-json/custom/v1/feedback',{method:'POST',headers:{'Content-Type':'application/json'},body:JSON.stringify(data)}).then(response=>response.json()).then(data=>{console.log('Feedback sent successfully:',data);}).catch((error)=>{console.error('Error sending feedback:',error);});}
cleanupPopup();}- clevermathgames.com
Receives the feedback POST containing the extension name, current page URL, extension version, issue type, and issue description.
Seven-day timer injects an onlineapp.pro paywall
Right Click Enable stores an install timestamp and, seven days later for new users, injects paywall scripts on activation.
Scripts load an onlineapp.pro iframe and call it to check paywall status before opening the subscription page.
You activate the extension after it has been installed for more than seven days.
The service worker checks the stored install date before deciding which scripts to inject.
The extension injects paywall code into the active tab and checks payment status online.
If the returned status requires payment, the worker opens the extension's subscription page.
The paywall path becomes eligible only after the stored install date is more than seven days old.
| Field | Value | Why it matters | |
|---|---|---|---|
Trial window | 7 days | Determines when the extension switches from normal activation to the paywall check. | |
Install timestamp | 1720828800000 | Records when the extension was installed on your browser profile. | |
Paywall ID | 237 | Identifies the onlineapp.pro paywall flow loaded by the extension. | |
Payment status request | https://onlineapp.pro/api/v1/paywall/237/user | Checks whether the paywall service considers this browser session paid or unpaid. |
The worker waits seven days, injects scripts, then checks paywall status
function setInstallDate() {
const installDate = new Date().getTime();
chrome.storage.local.set({
installDate: installDate,
newUser: true
}, () => {
console.log('Install date:', installDate, 'newUser:', true);
});
}const injectionCheck = await chrome.scripting.executeScript({
target: {
tabId
},
function: checkInjection
});
const isAlreadyInjected = injectionCheck?.[0]?.result || false;
if (!isAlreadyInjected) {
const trialOver = await new Promise((resolve) => {
const TRIAL_IN_MS = 7 * 24 * 60 * 60 * 1000;
chrome.storage.local.get(['installDate', 'newUser'], (data) => {
const {
installDate,
newUser
} = data;
if (!newUser) {
resolve(false);
return;
}
if (installDate) {
const currentDate = new Date().getTime();
const trialPeriodOver = ((currentDate - installDate) > TRIAL_IN_MS);
const installDateObj = new Date(installDate);
const currentDateObj = new Date(currentDate);
console.log('isTrialPeriodOver: ', 'trialPeriodOver:', trialPeriodOver, 'currentDate:', currentDateObj.toLocaleString(), 'installDate:', installDateObj.toLocaleString(), 'Time difference:', formatTimeDifference(currentDate - installDate));
resolve(trialPeriodOver);
} else {
setInstallDate();
resolve(false);
}
});
});
if (trialOver && !isPaywallGetUserRunning) {
isPaywallGetUserRunning = true;
try {
await chrome.scripting.executeScript({
target: {
tabId,
...properties,
allFrames: false
},
injectImmediately: true,
files: ['wall.js', '/data/inject/check-payment.js']
});
} catch (error) {
console.warn(error);
notify(error.message);
isPaywallGetUserRunning = false;
}
}
}async function isPaymentRequired(callback){try{const userData=await paywall.getUser();console.log('User Data:',userData);chrome.runtime.sendMessage({method:"paywall-getuser-completed"});if(userData.countryMatch!==true){return;}
if(userData.error==='Unauthorized'){callback();return;}
if(userData.paid!==true){callback();}}catch(error){console.error('Error fetching user data:',error);}}
function checkPayment(){if(window.pointers.status==='ready'){isPaymentRequired(()=>{chrome.runtime.sendMessage({method:"openPayWallTab"});});}else{chrome.runtime.sendMessage({method:"paywall-getuser-completed"});}}
checkPayment();The injected paywall library loads onlineapp.pro
_createAndAppendIframe: function() {
window.requestAnimationFrame(() => {
let e = () => {
let e = this._paywallDocumentRoot.createElement("iframe");
e.src = "https://onlineapp.pro/paywall/".concat(this.paywallId, "?v=2"), e.id = "paywall-".concat(this.paywallId), e.style.display = "none";
let a = this._paywallDocumentRoot.body || this._paywallDocumentRoot;
a ? a.appendChild(e) : console.warn("[PAYWALL ERROR] Paywall container not found")
};
"loading" === this._paywallDocumentRoot.readyState ? this._paywallDocumentRoot.addEventListener("DOMContentLoaded", e) : e()
})
},
getUser: async function() {
return await this._ensureInitialized(), this.makeRequest("https://onlineapp.pro/api/v1/paywall/".concat(this.paywallId, "/user"))
}
}, paywall.init("237")- onlineapp.pro
Hosts the paywall iframe and receives the paywall user-status request for paywall ID 237.