Is Risk Reminder Remover safe?
Risk Reminder Remover is medium risk. On product pages of supported shopping-agent sites, the extension checks an affiliate setting on by default. If the URL lacks its affiliate value, the content script adds a `ref` or `u` parameter and replaces the page with that address.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Affiliate tags added to shopping product URLs
On product pages of supported shopping-agent sites, the extension checks an affiliate setting on by default.
If the URL lacks its affiliate value, the content script adds a `ref` or `u` parameter and replaces the page with that address.
You open a product page on a supported shopping-agent site.
The content script runs on cnfans.com, mulebuy.com, joyagoo.com, orientdig.com, oopbuy.com, acbuy.com, and hoobuy.com.
The extension redirects the page after adding its affiliate value to the URL.
For most domains it writes `ref`; for acbuy.com it writes `u` and removes any existing `code` parameter.
| Field | Value | Why it matters | |
|---|---|---|---|
Product page address | https://www.cnfans.com/product?id=123456&ref=272747 | Shows which shopping product page you opened and is sent to the shopping site during the redirected navigation. | |
Affiliate tag | ref=272747 | Links the product-page visit to the extension's built-in affiliate value at the shopping site. | |
ACBuy affiliate tag | u=XNX5L3 | On ACBuy product pages, the extension uses a different parameter name but still adds its built-in affiliate value. |
The source stores the affiliate values as base64 strings and decodes them before rewriting the URL.
{
"cnfans.com": "272747",
"mulebuy.com": "200006620",
"joyagoo.com": "300112723",
"orientdig.com": "100073169",
"hoobuy.com": "utm_source=share&utm_medium=product_details&inviteCode=MXzeayxR",
"oopbuy.com": "utm_source=lium=product_details&inviteCode=WMYIG2K0N",
"acbuy.com": "XNX5L3"
}The affiliate redirect path in the shipped content script
function fetchAffiliateCode(hostOverride) {
const encodedAffiliateCodes = {
"cnfans.com": "MjcyNzQ3",
"mulebuy.com": "MjAwMDA2NjIw",
"joyagoo.com": "MzAwMTEyNzIz",
"orientdig.com": "MTAwMDczMTY5",
"hoobuy.com": "dXRtX3NvdXJjZT1zaGFyZSZ1dG1fbWVkaXVtPXByb2R1Y3RfZGV0YWlscyZpbnZpdGVDb2RlPU1YemVheXhS",
"oopbuy.com": "dXRtX3NvdXJjZT1saXVtPXByb2R1Y3RfZGV0YWlscyZpbnZpdGVDb2RlPVdNWUlHMkswTg==",
"acbuy.com": "WE5YNUwz"
};
const hostname = (hostOverride || window.location.hostname).replace(/^www\./, "");
return encodedAffiliateCodes[hostname] ? atob(encodedAffiliateCodes[hostname]) : "";
}function redirectToAffiliate() {
chrome.storage.sync.get({ affiliateEnabled: true }, function (data) {
if (!data.affiliateEnabled) return;
let url = new URL(window.location.href);
let hostname = url.hostname.replace(/^www\./, "");
let affiliateCode = fetchAffiliateCode();
if (url.pathname.includes("/product")) {
if (hostname === "acbuy.com") {
if (url.searchParams.get("u") !== affiliateCode) {
url.searchParams.set("u", affiliateCode);
url.searchParams.delete("code");
window.location.replace(url.toString());
}
} else if (
["cnfans.com", "mulebuy.com", "joyagoo.com", "orientdig.com", "hoobuy.com", "oopbuy.com"]
.includes(hostname)
) {
if (url.searchParams.get("ref") !== affiliateCode) {
url.searchParams.set("ref", affiliateCode);
window.location.replace(url.toString());
}
}
}
});
}if (document.readyState === "loading") {
document.addEventListener("DOMContentLoaded", () => {
redirectToAffiliate();
removeRiskReminder();
activateAgreeCheckbox();
checkInfringementRedirect();
maybeShowPendingRedirectPopup();
});
} else {
redirectToAffiliate();
removeRiskReminder();
activateAgreeCheckbox();
checkInfringementRedirect();
maybeShowPendingRedirectPopup();
}- cnfans.com
Receives product-page navigations with ref=272747 when the path contains /product.
- mulebuy.com
Receives product-page navigations with ref=200006620 when the path contains /product.
- joyagoo.com
Receives product-page navigations with ref=300112723 when the path contains /product.
- orientdig.com
Receives product-page navigations with ref=100073169 when the path contains /product.
- hoobuy.com
Receives product-page navigations with a ref value that decodes to utm_source=share&utm_medium=product_details&inviteCode=MXzeayxR.
- oopbuy.com
Receives product-page navigations with a ref value that decodes to utm_source=lium=product_details&inviteCode=WMYIG2K0N.
- acbuy.com
Receives product-page navigations with u=XNX5L3, and the extension removes any existing code parameter before redirecting.
Recreates the extension's affiliate URL rewriting for representative supported shopping product URLs.
const encodedAffiliateCodes = {
"cnfans.com": "MjcyNzQ3",
"mulebuy.com": "MjAwMDA2NjIw",
"joyagoo.com": "MzAwMTEyNzIz",
"orientdig.com": "MTAwMDczMTY5",
"hoobuy.com": "dXRtX3NvdXJjZT1zaGFyZSZ1dG1fbWVkaXVtPXByb2R1Y3RfZGV0YWlscyZpbnZpdGVDb2RlPU1YemVheXhS",
"oopbuy.com": "dXRtX3NvdXJjZT1saXVtPXByb2R1Y3RfZGV0YWlscyZpbnZpdGVDb2RlPVdNWUlHMkswTg==",
"acbuy.com": "WE5YNUwz"
};
function fetchAffiliateCode(hostname) {
const normalized = hostname.replace(/^www\./, "");
return encodedAffiliateCodes[normalized]
? Buffer.from(encodedAffiliateCodes[normalized], "base64").toString("utf8")
: "";
}
function rewriteProductUrl(input) {
const url = new URL(input);
const hostname = url.hostname.replace(/^www\./, "");
const affiliateCode = fetchAffiliateCode(hostname);
if (!url.pathname.includes("/product") || !affiliateCode) return url.toString();
if (hostname === "acbuy.com") {
if (url.searchParams.get("u") !== affiliateCode) {
url.searchParams.set("u", affiliateCode);
url.searchParams.delete("code");
}
} else if (["cnfans.com", "mulebuy.com", "joyagoo.com", "orientdig.com", "hoobuy.com", "oopbuy.com"].includes(hostname)) {
if (url.searchParams.get("ref") !== affiliateCode) {
url.searchParams.set("ref", affiliateCode);
}
}
return url.toString();
}
const samples = [
"https://www.cnfans.com/product?id=123456",
"https://www.mulebuy.com/product/987654",
"https://www.joyagoo.com/product?id=24680",
"https://www.orientdig.com/product/13579",
"https://www.hoobuy.com/product?id=112233",
"https://www.oopbuy.com/product?id=445566",
"https://www.acbuy.com/product?id=778899&code=OLDVALUE"
];
for (const sample of samples) {
console.log(`${sample} -> ${rewriteProductUrl(sample)}`);
}
- 1node affiliate-url-reproducer.js
What it can do
Permissions this extension asks for, as declared in version 1.9. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on cnfans.com
https://*.cnfans.com/*
Read and change your data on mulebuy.com
https://*.mulebuy.com/*
Read and change your data on joyagoo.com
https://*.joyagoo.com/*
Read and change your data on orientdig.com
https://*.orientdig.com/*
Read and change your data on oopbuy.com
https://*.oopbuy.com/*
Read and change your data on acbuy.com
https://*.acbuy.com/*
Read and change your data on hoobuy.com
https://*.hoobuy.com/*
Act on the current tab, but only after you click the extension
activeTab
Run its own code inside the pages you visit
scripting
Store data in your browser
storage