Is WPS浏览器助手:文档在线阅读编辑 safe?

Medium risk

WPS浏览器助手 is medium risk. Visiting any page triggers a page-view event to a Kingsoft analytics service with URL, title, and referrer, firing all session since content scripts cover <all_urls>. Reporting ships on by default, encrypted on the wire. Opt-out in Options.

金山PDFv4.1.6Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Page URL, Title and Referrer Sent to Kingsoft Analytics on Every Site

Visiting any page triggers a page-view event to a Kingsoft analytics service with URL, title, and referrer, firing all session since content scripts cover <all_urls>.

Reporting ships on by default, encrypted on the wire.

Opt-out in Options.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You navigate to any web page, any site, anywhere.

The extension did this

The extension records the visit and sends the page URL, its title, and the page you came from to a Kingsoft analytics service.

No interaction with a WPS document is required. The reporting is on by default and runs on every site because the extension's content scripts and host access cover <all_urls>.

02EvidenceFIELD TABLE
What each page-view event carries:
FieldValueWhy it matters
The page URL you are visiting
https://en.wikipedia.org/wiki/EncryptionThe exact page you are on, including any tracking or identifying parameters in the address.
The page title
Encryption - WikipediaThe title of the page you are viewing, which often describes the content.
The page you came from (referrer)
https://www.google.com/search?q=encryptionWhere you were before this page, builds a chain of where you have been.
03EvidenceOPAQUE REVEAL
Why you can't catch this in DevTools

On the wire each event body is encrypted, so you cannot read it in your browser's network inspector. Decrypting a captured request with the key shipped inside the extension reveals the page-view contents.

What's actually being sent
{
  "name": "_page_view",
  "title": "Encryption - Wikipedia",
  "url": "https://en.wikipedia.org/wiki/Encryption",
  "refer": "https://www.google.com/search?q=encryption",
  "_encrypted_fields": "title,url,refer"
}
04EvidenceCODE COMPARE
The code that does this

The code that builds and labels the page-view event, from the extension's shipping source.

What it actually does
Reporter config: endpoints + hardcoded AES key
// Analytics reporter config
Reporter.defaults = {
  dynamicUrl: 'https://dw-online.ksosoft.com',
  sendUrl:    'https://shuc-js.ksord.com/bat/js/cors'
};
Reporter.use(transport, {
  aesKey: 'ZctYg7JjXcPySXxw',   // 16-byte AES-128 key, shipped in the extension
  rsaKey: '8762DEC3...'
});
The page-view event assembler
// Built on navigation; carries the page you are on.
const event = new DWEvent('_page_view', {
  ...common,
  ...defaults._page_view,
  title: page.getTitle(),    // current page title
  url:   page.getUrl(),      // current page URL
  refer: page.getReferer()   // the page you came from
});
Fields marked for encryption on a page-view
// These three fields are encrypted before the body is sent.
if (event.name === '_page_view') {
  encryptedFields = ['title', 'url', 'refer'];
}
05EvidenceARTIFACT
Check if you're affected

Decrypts captured DW Reporter event bodies using the AES-128-CBC key shipped in the extension, revealing the page-view url/title/refer fields.

RequiresNode.js 18+
decrypt.js · js
#!/usr/bin/env node
// Decrypts WPS browser helper DW Reporter analytics bodies.
// rn.Reporter.use(transport, { aesKey: 'ZctYg7JjXcPySXxw' })
//   key = UTF8('ZctYg7JjXcPySXxw') -> 16 bytes -> AES-128
//   iv  = CryptoJS.enc.Utf8.parse('') -> 16 zero bytes
//   mode = CBC (CryptoJS default), padding = Pkcs7, wire = base64
const crypto = require('crypto');
const fs = require('fs');

const KEY = Buffer.from('ZctYg7JjXcPySXxw', 'utf8'); // 16 bytes -> AES-128
const IV = Buffer.alloc(16, 0);                       // zero IV

function decrypt(b64) {
  const ct = Buffer.from(b64, 'base64');
  const d = crypto.createDecipheriv('aes-128-cbc', KEY, IV);
  d.setAutoPadding(true); // Pkcs7
  return Buffer.concat([d.update(ct), d.final()]).toString('utf8');
}

const rows = JSON.parse(fs.readFileSync(process.argv[2] || 'bodies.json', 'utf8'));
let ok = 0;
for (const r of rows) {
  try {
    console.log(`\n=== ${r.id} (${r.source}) ===`);
    console.log(decrypt(r.body));
    ok++;
  } catch (e) {
    console.log(`\n=== ${r.id} DECRYPT FAILED: ${e.message} ===`);
  }
}
console.log(`\nDecrypted ${ok}/${rows.length} bodies.`);
How to run it
  1. 1
    Save captured request bodies to bodies.json as [{"id":"...","source":"...","body":"<base64>"}].
  2. 2
    Run: node decrypt.js bodies.json.
  3. 3
    Read the decrypted _page_view envelopes.
06EvidenceTHIRD PARTY LIST
Where the page-view events are sent:
  • shuc-js.ksord.com

    Receives the encrypted page-view event bodies (DW Reporter sendUrl, /bat/js/cors). Operated by Kingsoft.

  • dw-online.ksosoft.com

    DW Reporter dynamic-config endpoint (dynamicUrl). Kingsoft analytics domain.

What it can do

Permissions this extension asks for, as declared in version 4.1.6. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    <all_urls>

  • See every page you navigate to, as you navigate to it

    webNavigation

  • Watch every request your browser makes

    webRequest

  • Start, monitor and manage your downloads

    downloads

  • Store data in your browser

    storage

  • See the address and title of every tab you have open

    tabs

  • Read and change cookies, including the ones that keep you signed in

    cookies

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

  • Block and redirect the requests your browser makes

    declarativeNetRequest

  • Receive push messages from its developer's servers

    gcm

  • Add items to the right-click menu

    contextMenus

  • Show a panel beside the page

    sidePanel

Updated 21 September 2026blegnhaaimfcklgddeegngmanbnfopog