Is Web Safety safe?

Medium risk

Web Safety is medium risk. On install, update, daily startup, and blocklist refresh, Web Safety sends a browser profile and a permanent UUID to flow.lavasoft.com: browser, OS, locale, version, install date. DA captured the full body on both events.

websafetyv2.0.0Chrome Web Store
48Risk
Who publishes it

7270356 Canada Inc. - 3 other listings from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
websafety
Declared legal entity
7270356 Canada Inc.
Registered address
7075 Pl. Robert Joncas #142, Montreal, QC H4M 2Z2, CA
Registered contact
7270356 Canada Inc.

Same store account

1 other listing published from this account, 60k+ users between them, none of them carrying a finding.

Same operator - 2 listings

Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.

Shared hosts - 1 hostname

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

flow.lavasoft.com
Also called by 5 other listings, including OmniSearch, Adaware AdBlock

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Browser fingerprint and install ID sent to Lavasoft on install and refresh

On install, update, daily startup, and blocklist refresh, Web Safety sends a browser profile and a permanent UUID to flow.lavasoft.com: browser, OS, locale, version, install date.

DA captured the full body on both events.

Severity
Medium unwanted
Type
Unexpected
CWE
CWE-359
Source
Dynamic sandbox
What actually happens
You did this

You install or update Web Safety, start it after a day of inactivity, or it refreshes its blocklists.

The extension did this

The extension assembles a browser profile plus a permanent per-install ID and POSTs it to flow.lavasoft.com.

No user action beyond having the extension installed. Fires on install, update, daily startup, and on each blocklist-download event.

What is sent to flow.lavasoft.com in each event
  • Install ID
    c992d108-d7a8-4428-a924-fc3f670eb7cf

    A UUID generated once at install and stored permanently, so the same install can be recognized across every later event.

  • Extension ID
    mfhcmdonhekjhfbjmeacdjbhlfgpjabp

    The Chrome extension identifier, confirming which extension sent the data.

  • Browser family and version
    Chrome 148.0.0.0

    Which browser you run and its exact version.

  • Operating system
    linux

    Your platform, derived from the browser.

  • Browser and extension locale
    en-US

    Your language settings.

  • Extension version
    2.0.0

    Which version of Web Safety you have installed.

  • Install date
    2026-06-15T17:27:14.202Z

    When the extension was first installed, to the millisecond.

  • Marketing attribution fields
    PartnerID, CampaignID, sourceTraffic (empty in this capture)

    PartnerID, CampaignID, OfferID, CLID and other affiliate tags read from a webcompanion.com landing URL at install, else empty.

Captured request
POSThttps://flow.lavasoft.com/v1/event-stat?ProductID=ws&Type=CompleteInstall
Body
{  "Data": {    "BrowserFamily": "Chrome",    "BrowserVersion": "148.0.0.0",    "BrowserLocale": "en-US",    "Platform": "linux",    "ExtensionVersion": "2.0.0",    "ExtensionLocale": "en-US",    "installDate": "2026-06-15T17:27:14.202Z",    "installId": "c992d108-d7a8-4428-a924-fc3f670eb7cf",    "CLID": "",    "CampaignID": "",    "IK": "",    "MK": "",    "OfferID": "",    "PartnerID": "",    "extensionID": "mfhcmdonhekjhfbjmeacdjbhlfgpjabp",    "sourceTraffic": ""  }}
The code that does this

The code that builds and sends the event, from the extension's shipping source.

Readable version

telemetry.sendEvent — POSTs the assembled object

// Builds the event URL (flowUrl + ?ProductID=ws&Type=<event>) and POSTs// the assembled data object as JSON to flow.lavasoft.com.function sendEvent(eventType, data) {  eventParameters.Type = eventType;                       // CompleteInstall | DailyActivity | CompleteUpdate | AcsListDownload  const url = flowUrl + toQueryString(eventParameters);   // https://flow.lavasoft.com/v1/event-stat?ProductID=ws&Type=...  fetch(url, {    method: 'POST',    headers: { 'Content-Type': 'application/json' },    body: JSON.stringify(data)                             // { Data: { browser profile + installId + extensionID + attribution } }  });}

systemUtil.browserEnvironmentData — the browser fingerprint

// Reads the browser/OS/locale/version profile that is included in every event.function browserEnvironmentData() {  const info = getBrowserInfo();          // parsed from navigator.userAgent  this.BrowserFamily   = info.name;       // e.g. 'Chrome'  this.BrowserVersion  = info.version;    // e.g. '148.0.0.0'  this.BrowserLocale   = info.lang;       // navigator.language  this.Platform        = getOSName();     // 'windows' | 'mac' | 'linux' | 'other'  this.ExtensionVersion = manifest.version;  this.ExtensionLocale  = chrome.i18n.getUILanguage();}
Where the data is sent
    • flow.lavasoft.com

    Lavasoft/Avanquest telemetry endpoint receiving the browser profile, install UUID, extension ID, and attribution fields on install, update, startup, blocklist refresh.

What it can do

Permissions this extension asks for, as declared in version 2.0.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    *://*/*

  • Store data in your browser

    storage

  • See the address and title of every tab you have open

    tabs

  • Watch every request your browser makes

    webRequest

  • Store an unlimited amount of data in your browser

    unlimitedStorage

  • Block and redirect the requests your browser makes

    declarativeNetRequest

Updated 30 September 2026mfhcmdonhekjhfbjmeacdjbhlfgpjabp