Is Web Safety safe?
Web Safety is medium risk. On install, update, daily startup, and blocklist refresh, Web Safety sends a browser profile and a permanent UUID to flow.lavasoft.com: browser, OS, locale, version, install date. DA captured the full body on both events.
Who publishes it7270356 Canada Inc. - 3 other listings from the same operator, none carrying a finding
7270356 Canada Inc. - 3 other listings from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
1 other listing published from this account, 60k+ users between them, none of them carrying a finding.
Same operator - 2 listings
Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.
Shared hosts - 1 hostname
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Browser fingerprint and install ID sent to Lavasoft on install and refresh
On install, update, daily startup, and blocklist refresh, Web Safety sends a browser profile and a permanent UUID to flow.lavasoft.com: browser, OS, locale, version, install date.
DA captured the full body on both events.
- Severity
- Medium unwanted
- Type
- Unexpected
- CWE
- CWE-359
- Source
- Dynamic sandbox
You install or update Web Safety, start it after a day of inactivity, or it refreshes its blocklists.
The extension assembles a browser profile plus a permanent per-install ID and POSTs it to flow.lavasoft.com.
No user action beyond having the extension installed. Fires on install, update, daily startup, and on each blocklist-download event.
- Install IDc992d108-d7a8-4428-a924-fc3f670eb7cf
A UUID generated once at install and stored permanently, so the same install can be recognized across every later event.
- Extension IDmfhcmdonhekjhfbjmeacdjbhlfgpjabp
The Chrome extension identifier, confirming which extension sent the data.
- Browser family and versionChrome 148.0.0.0
Which browser you run and its exact version.
- Operating systemlinux
Your platform, derived from the browser.
- Browser and extension localeen-US
Your language settings.
- Extension version2.0.0
Which version of Web Safety you have installed.
- Install date2026-06-15T17:27:14.202Z
When the extension was first installed, to the millisecond.
- Marketing attribution fieldsPartnerID, CampaignID, sourceTraffic (empty in this capture)
PartnerID, CampaignID, OfferID, CLID and other affiliate tags read from a webcompanion.com landing URL at install, else empty.
{ "Data": { "BrowserFamily": "Chrome", "BrowserVersion": "148.0.0.0", "BrowserLocale": "en-US", "Platform": "linux", "ExtensionVersion": "2.0.0", "ExtensionLocale": "en-US", "installDate": "2026-06-15T17:27:14.202Z", "installId": "c992d108-d7a8-4428-a924-fc3f670eb7cf", "CLID": "", "CampaignID": "", "IK": "", "MK": "", "OfferID": "", "PartnerID": "", "extensionID": "mfhcmdonhekjhfbjmeacdjbhlfgpjabp", "sourceTraffic": "" }}The code that builds and sends the event, from the extension's shipping source.
telemetry.sendEvent — POSTs the assembled object
// Builds the event URL (flowUrl + ?ProductID=ws&Type=<event>) and POSTs// the assembled data object as JSON to flow.lavasoft.com.function sendEvent(eventType, data) { eventParameters.Type = eventType; // CompleteInstall | DailyActivity | CompleteUpdate | AcsListDownload const url = flowUrl + toQueryString(eventParameters); // https://flow.lavasoft.com/v1/event-stat?ProductID=ws&Type=... fetch(url, { method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify(data) // { Data: { browser profile + installId + extensionID + attribution } } });}systemUtil.browserEnvironmentData — the browser fingerprint
// Reads the browser/OS/locale/version profile that is included in every event.function browserEnvironmentData() { const info = getBrowserInfo(); // parsed from navigator.userAgent this.BrowserFamily = info.name; // e.g. 'Chrome' this.BrowserVersion = info.version; // e.g. '148.0.0.0' this.BrowserLocale = info.lang; // navigator.language this.Platform = getOSName(); // 'windows' | 'mac' | 'linux' | 'other' this.ExtensionVersion = manifest.version; this.ExtensionLocale = chrome.i18n.getUILanguage();}- flow.lavasoft.com
Lavasoft/Avanquest telemetry endpoint receiving the browser profile, install UUID, extension ID, and attribution fields on install, update, startup, blocklist refresh.
What it can do
Permissions this extension asks for, as declared in version 2.0.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
*://*/*
Store data in your browser
storage
See the address and title of every tab you have open
tabs
Watch every request your browser makes
webRequest
Store an unlimited amount of data in your browser
unlimitedStorage
Block and redirect the requests your browser makes
declarativeNetRequest