Is XLS Editor safe?
XLS Editor is high risk. On first run, this extension generates a random 10-character ID stored permanently, attached to every URL report sent to offidocs.com. This links every page you visit into one profile tied to your install, with no way to reset it.…
Who publishes itofficeonlinesystems - 26 other listings from the same operator, 17 of them carrying a finding
officeonlinesystems - 26 other listings from the same operator, 17 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
19 other listings published from this account, 1.5M+ users between them. 14 of them carry a finding.
Same operator - 7 listings
Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.
Shared hosts - 1 hostname
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Extension assigns a permanent tracking ID to your browser install
On first run, this extension generates a random 10-character ID stored permanently, attached to every URL report sent to offidocs.com.
This links every page you visit into one profile tied to your install, with no way to reset it.
The extension installs and runs for the first time on your browser.
It generates a permanent random identifier and stores it locally, then appends it to every URL report sent to offidocs.com.
The ID is never displayed to you and has no visible reset mechanism in the extension UI.
'username' is the permanent tracking ID sent with every navigation report. 'offidocscloud' controls URL exfil (1=on, 0=off); default is 1.
chrome.storage.local key 'offidocs_key'{
"username": "a7kx2mq9nf",
"offidocscloud": "1"
}Tracking ID generation and persistence (websecure.js:60-95)
async function extractaudio(urlxx) {
const offidocs_key = 'offidocs_key';
var datax = { username: null, offidocscloud: null };
var username = '';
// Load stored data
let storageResult = await chrome.storage.local.get([offidocs_key]);
if (offidocs_key in storageResult) {
datax = storageResult[offidocs_key];
}
// Generate and persist tracking ID if not present
if (datax.username) {
username = datax.username;
} else {
username = '' + randomString(10) + ''.toLowerCase(); // new persistent ID
datax.username = username;
}
// Default tracking to enabled
if (datax.offidocscloud) {
offidocscloud = datax.offidocscloud;
} else {
offidocscloud = '1'; // enabled by default
datax.offidocscloud = '1';
}
// Persist changes
var data = {};
data[offidocs_key] = datax;
await chrome.storage.local.set(data);
var un = username;
if (datax.offidocscloud == '0') return; // opt-out gate
// Send URL + tracking ID to offidocs.com
let cfgv = await fetch(
'https://www.offidocs.com/media/system/app/checkdownloadxlseditorx_2_nav.php'
+ '?filepath=' + bin2hex(urlxx)
+ '&hex=1&u=' + un
+ '&s=' + servicexx
);
}- www.offidocs.com
Receives the persistent user tracking ID as the &u= parameter on every URL navigation report. The same operator publishes this extension.
Extension reports every URL you visit to offidocs.com in real time
Every time you navigate, this extension sends the page's full URL, hex-encoded, to offidocs.com with a persistent install ID, automatically, with no indicator.
A popup opt-out exists, but tracking defaults on and most users never see it.
You navigate to any website, any page, on any domain.
The extension encodes the full URL and sends it to offidocs.com with your persistent user ID.
This happens automatically on every navigation, with no UI indication and no per-site allowlist.
| Field | Value | Why it matters | |
|---|---|---|---|
The URL you are visiting | https://mail.google.com/mail/u/0/#inbox/FMfcgzQZTkFprjVlMQnXzSlkbPMknRpg | The full address of every page you navigate to, including query strings and path. | |
Your persistent user ID | a7kx2mq9nf | A 10-character random identifier generated on first run and stored permanently, used to link all your browsing reports together. |
The visited URL is hex-encoded by bin2hex() before being placed in the filepath= query parameter. The server receives the hex string and can decode it to the original URL.
https://mail.google.com/mail/u/0/#inbox/FMfcgzQZTkFprjVlMQnXzSlkbPMknRpg
Navigation listener → URL exfil path (websecure.js)
function getTabInfo(tabId) {
chrome.tabs.get(tabId, function(tab) {
if (
(tab.url.indexOf('offidocs') == -1) &&
(tab.url.indexOf('http') !== -1) &&
(lastUrl != tab.url)
) {
urlx = tab.url;
extractaudio(urlx); // encodes + sends URL to offidocs.com
lastUrl = tab.url;
}
});
}- www.offidocs.com
Receives the hex-encoded visited URL and persistent user ID on every page navigation. offidocs.com is operated by the same developer who publishes this extension.
Popup Fetches File List From Browsing History
Opening the XLS Editor popup sends a GET to offidocs.com with the stored user ID.
The service-worker path reporting visited URLs uses the same ID, letting the popup endpoint return a server-selected HTML file list tied to that activity.
You open the XLS Editor popup or click its Detection control.
The extension asks offidocs.com for a file list tied to the stored user identifier.
The response is written directly into the popup area labeled as files detected in the current webpage.
| Field | Value | Why it matters | |
|---|---|---|---|
Stored user ID | x7k2m9q4az (illustrative) | Lets the server connect the popup request to the same browser profile over time. | |
Visited page URL | https://docs.example.com/reports/q2.xlsx (illustrative) | Shows which pages were visited before the popup asks for matching files. | |
Returned file-list HTML | <a href="https://www.offidocs.com/media/system/app/view_edit_xlseditor_nav.php?filepath=68747470733a2f2f646f63732e6578616d706c652e636f6d2f7265706f7274732f71322e786c7378&u=x7k2m9q4az">q2.xlsx</a> (illustrative) | Controls what file links the popup displays after it asks the server for detected files. |
Popup fetches a server file list; service worker reports visited URLs
var xhr1 = new XMLHttpRequest();
xhr1.open('GET', 'https://www.offidocs.com/media/system/app/checkdownloadxlseditorr_2_nav.php?u=' + username, true);
xhr1.onload = function (e) {
if (xhr1.readyState === 4) {
if (xhr1.status === 200) {
//console.log(xhr1.responseText);
var response1 = xhr1.responseText;
listfilesx = document.getElementById('listfilesx');
listfilesx.innerHTML = "<p>List of files detected in this webpage. Click to edit:</p> " + response1;
} else {
listfilesx = document.getElementById('listfilesx');
listfilesx.innerHTML = "<p>No files detected</p>";
}
}
};
xhr1.onerror = function (e) {
listfilesx = document.getElementById('listfilesx');
listfilesx.innerHTML = "<p>No files detected</p>";
};
xhr1.send();function getTabInfo(tabId) {
chrome.tabs.get(tabId, function(tab) {
if ( ( tab.url.indexOf("offidocs") == -1 ) && ( tab.url.indexOf("http") !== -1 ) && ( lastUrl != tab.url) ) {
//console.log(" Changed tab.url " + tab.url);
urlx = tab.url;
extractaudio(urlx);
lastUrl = tab.url;
}
});
}
function websecure() {
this.init = function () {
chrome.tabs.onActivated.addListener(function(activeInfo) {
activeTabId = activeInfo.tabId;
getTabInfo(activeTabId);
});
chrome.tabs.onUpdated.addListener(function(tabId, changeInfo, tab) {
//if(activeTabId == tabId) {
getTabInfo(tabId);
//}
});
};
}
async function extractaudio(urlxx) {
const offidocs_key = "offidocs_key";
var datax = { username: null, offidocscloud: null };
var username = "";
var offidocscloud = "";
let storageResult = await chrome.storage.local.get([offidocs_key]);
if (offidocs_key in storageResult) {
datax = storageResult[offidocs_key]
}
if ( datax.username ) {
username = datax.username;
}
else {
username = "" + randomString(10) + "".toLowerCase();
datax.username = username;
}
if ( datax.offidocscloud ) {
offidocscloud = datax.offidocscloud;
}
else {
offidocscloud = "1";
datax.offidocscloud = "1";
}
var data = {};
data[offidocs_key] = datax;
await chrome.storage.local.set(data);
var un = username;
if ( datax.offidocscloud == "0")
return;
let cfgv = await fetch('https://www.offidocs.com/media/system/app/checkdownloadxlseditorx_2_nav.php?filepath=' + bin2hex(urlxx) + '&hex=1&u=' + un + "&s=" + servicexx);
if (cfgv.status === 200) {
let fbv = await cfgv.text();
//console.log(fbv);
var nbv = fbv;
if ( nbv.indexOf("302") !== -1 ) {
var ybv = 'https://www.offidocs.com/media/system/app/view_edit_xlseditor_nav.php?filepath=' + bin2hex(urlxx) + '&u=' + un;
//chrome.tabs.create({ url: ybv });
chrome.tabs.update(chrome.tabs.getCurrent().id, {url: ybv});
}
}
}
function bin2hex (bin)
{
var i = 0, l = bin.length, chr, hex = ''
for (i; i < l; ++i)
{
chr = bin.charCodeAt(i).toString(16)
hex += chr.length < 2 ? '0' + chr : chr
}
return hex
}- www.offidocs.com
Receives the stored user identifier and visited-page URL reports, then returns the popup file-list HTML.
What it can do
Permissions this extension asks for, as declared in version 2.15.2. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Store data in your browser
storage
See the address and title of every tab you have open
tabs