Is SaleFlow - продвинутая аналитика Wildberries safe?
SaleFlow reads Wildberries' own anti-bot session tokens from the page and sends them to its own backend on every API call.
While active on wildberries.ru, search.wb.ru, or catalog.wb.ru, SaleFlow reads the site's bot-detection cookies (x_wbaas_token, _wbauid) and a proof-of-work token stored in localStorage, then attaches them as headers on roughly 40 requests to its own server at box.saleflow.pro. These are Wildberries' own tokens for proving a session has passed its bot checks, not data SaleFlow's backend needs to talk to Wildberries directly, so forwarding them lets SaleFlow's servers reuse a cleared, real-user session when querying Wildberries on the extension's behalf.
Who publishes itsaleflow - 1 other listing from the same operator, 1 of them carrying a finding
saleflow - 1 other listing from the same operator, 1 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
1 other listing published from this account, 4k+ users between them. 1 of them carries a finding.
Shared hosts - 1 hostname
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
SaleFlow copies your Wildberries anti-bot tokens to its own server
Code analysis shows the extension copies Wildberries' anti-bot session cookies and a proof-of-work token from your browser, then sends them as headers to the vendor's own server, box.saleflow.pro.
You open a product, search or catalog page on wildberries.ru with the extension installed.
The extension copies Wildberries' own anti-bot cookies and proof-of-work token and sends them as headers to box.saleflow.pro.
Code analysis shows this on roughly 40 different API calls the extension's widget makes.
| Field | Value | Why it matters | |
|---|---|---|---|
Anti-bot session cookie | x_wbaas_token=8f3ac21b9e4d47a1b6c0d92e5f7a1c34 | Marks your browser as one that already passed Wildberries' bot check for this session. | |
Visitor ID cookie | _wbauid=17389f2c-6b41-4e05-9a3d-2c1e0b8f4a92 | Ties every request to your specific Wildberries visitor session. | |
Proof-of-work token | session-pow-token = {"token":"a91cf3e6b8d24d10a7f5c9e2b6d4f0e1"} | A computed answer proving your browser solved Wildberries' anti-bot puzzle. |
The shared request interceptor that attaches the copied tokens
// Reads Wildberries' own anti-bot proof-of-work token out of this site's localStorage
function getSessionPowToken() {
const result = localStorage.getItem("session-pow-token"); // set by wildberries.ru itself
if (!result) return null;
return JSON.parse(result);
}
// Every call through $api() goes to the EXTENSION VENDOR'S server, not Wildberries
var $api = axios.create({
baseURL: "https://box.saleflow.pro/api",
paramsSerializer: { serialize: (params) => query_string_default.stringify(params, { arrayFormat: "comma" }) }
});
$api.interceptors.request.use(async (config) => {
// Copy Wildberries' anti-bot session cookie onto the outgoing request
const wbaasToken = await window.cookieStore.get("x_wbaas_token");
if (wbaasToken?.value) config.headers.set("x-wbaas-token", wbaasToken.value);
// Copy Wildberries' visitor-ID cookie onto the outgoing request
const wbauid = await window.cookieStore.get("_wbauid");
if (wbauid?.value) config.headers.set("wbauid", wbauid.value);
// Copy the anti-bot proof-of-work answer onto the outgoing request
const sessionPow = getSessionPowToken();
if (sessionPow) config.headers.set("x-pow", sessionPow.token);
return config; // request now carries WB's own bot-check credentials to a third server
});Watches outbound requests from a wildberries.ru tab and flags any that carry the copied anti-bot tokens toward box.saleflow.pro.
// wb-saleflow-token-check.js
// Paste into the DevTools console on a wildberries.ru tab, then browse a
// product, search or catalog page while the SaleFlow extension is active.
(function () {
const watched = ["x-wbaas-token", "wbauid", "x-pow"];
function report(url, headerBag) {
const seen = {};
for (const name of watched) {
const value = typeof headerBag.get === "function" ? headerBag.get(name) : headerBag[name];
if (value) seen[name] = value;
}
if (Object.keys(seen).length === 0) return;
console.log("[wb-saleflow-token-check] outbound to", url, seen);
console.log(" x_wbaas_token cookie:", document.cookie.match(/x_wbaas_token=([^;]+)/)?.[1]);
console.log(" _wbauid cookie:", document.cookie.match(/_wbauid=([^;]+)/)?.[1]);
console.log(" session-pow-token:", localStorage.getItem("session-pow-token"));
}
const origFetch = window.fetch;
window.fetch = function (input, init) {
const url = typeof input === "string" ? input : input.url;
if (url && url.includes("box.saleflow.pro/api")) {
report(url, (init && init.headers) || {});
}
return origFetch.apply(this, arguments);
};
const origOpen = XMLHttpRequest.prototype.open;
const origSetHeader = XMLHttpRequest.prototype.setRequestHeader;
XMLHttpRequest.prototype.open = function (method, url) {
this.__wbUrl = url;
this.__wbHeaders = {};
return origOpen.apply(this, arguments);
};
XMLHttpRequest.prototype.setRequestHeader = function (name, value) {
if (this.__wbHeaders) this.__wbHeaders[name.toLowerCase()] = value;
return origSetHeader.apply(this, arguments);
};
const origSend = XMLHttpRequest.prototype.send;
XMLHttpRequest.prototype.send = function () {
if (this.__wbUrl && this.__wbUrl.includes("box.saleflow.pro/api")) {
report(this.__wbUrl, this.__wbHeaders || {});
}
return origSend.apply(this, arguments);
};
console.log("[wb-saleflow-token-check] watching for box.saleflow.pro/api requests...");
})();
- 1Open wildberries.ru and log in or just browse.
- 2Open DevTools > Console.
- 3Paste this script and press Enter.
- 4Load a product or catalog page so the widget fetches data.
- 5Read the logged header values.
Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.
Where it sends data
Destinations our analysis observed SaleFlow - продвинутая аналитика Wildberries contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- box.saleflow.pro
SaleFlow - продвинутая аналитика Wildberries sends data to box.saleflow.pro. No other extension we have analysed sends data here.