Is "URL Tracker Redactor" on Chrome Web Store Safe to Install?

[email protected] · chrome · v1.0.5

While surfing the web on mobile devices you pay for the amount of data transmitted to and from your browser. By eliminating calls to advertising and data harvesting networks this extension conserves your precious bandwidth for your direct use. You can save money on the data package in you mobile phone bill with this extension As added bonus is that this conservation also makes your browsing faster. Using cookies for tracking your every move across the internet is old-fashioned. Now the tracking is embedded into the links them selves. This extension removes some of the most common tracking tags - to free you from the tight embrace of targeted manipulation by websites. The extension is written in the new Manifest V3 format advanced by Google and is therefore future-proof in the near-to-medium term. Likewise it is written without any javascript to safeguard the security and privacy of the user. It contains no code that can be subverted by others.

Risk Assessment

Analyzed
40.16
out of 100
MEDIUM

93 security findings detected across all analyzers

Chrome extension requesting 3 permissions

Severity Breakdown

0
Critical
18
High
75
Medium
0
Low
0
Info

Finding Categories

18
Malware Signatures
63
IoC Indicators

YARA Rules Matched

5 rules(18 hits)
postinstall network communication postinstall file download postinstall file manipulation postinstall crypto operations postinstall system command

Requested Permissions

3 permissions
*://*/*
Dangerous
background
Low
declarativeNetRequest
Low

About This Extension

While surfing the web on mobile devices you pay for the amount of data transmitted to and from your browser. By eliminating calls to advertising and data harvesting networks this extension conserves your precious bandwidth for your direct use. You can save money on the data package in you mobile phone bill with this extension As added bonus is that this conservation also makes your browsing faster. Using cookies for tracking your every move across the internet is old-fashioned. Now the tracking is embedded into the links them selves. This extension removes some of the most common tracking tags - to free you from the tight embrace of targeted manipulation by websites. The extension is written in the new Manifest V3 format advanced by Google and is therefore future-proof in the near-to-medium term. Likewise it is written without any javascript to safeguard the security and privacy of the user. It contains no code that can be subverted by others.

Detailed Findings

18 total

YARA Rule Matches

5 rules

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

URLs
20
IP Addresses
1
Domains
41
Strings
63

All Indicators · 63

Domain
detected Domain: taboola.com

XIOC detected Domain: taboola.com

extracted_from_files

URL
detected URL: https://tags.tiqcdn.com/utag/teg/core/prod/utag[

XIOC detected URL: https://tags.tiqcdn.com/utag/teg/core/prod/utag[

extracted_from_files

URL
detected URL: https://[

XIOC detected URL: https://[

extracted_from_files

URL
detected URL: https://www.linkedin.com/*

XIOC detected URL: https://www.linkedin.com/*

extracted_from_files

URL
detected URL: https://www.google-analytics.com/analytics.js

XIOC detected URL: https://www.google-analytics.com/analytics.js

extracted_from_files

URL
detected URL: https://www.facebook.com/tr

XIOC detected URL: https://www.facebook.com/tr

extracted_from_files

URL
detected URL: https://snap.licdn.com/li.lms-analytics/insight.min.js

XIOC detected URL: https://snap.licdn.com/li.lms-analytics/insight.min.js

extracted_from_files

URL
detected URL: https://sb.scorecardresearch.com/)([a-z0-9/]*beacon.js

XIOC detected URL: https://sb.scorecardresearch.com/)([a-z0-9/]*beacon.js

extracted_from_files

URL
detected URL: https://connect.facebook.net/en_US/fbevents.js

XIOC detected URL: https://connect.facebook.net/en_US/fbevents.js

extracted_from_files

URL
detected URL: https://[a-z

XIOC detected URL: https://[a-z

extracted_from_files

Domain
detected Domain: permutive.com

XIOC detected Domain: permutive.com

extracted_from_files

Domain
detected Domain: collector.brandmetrics.com

XIOC detected Domain: collector.brandmetrics.com

extracted_from_files

Domain
detected Domain: uk.bs

XIOC detected Domain: uk.bs

extracted_from_files

Domain
detected Domain: clients2.google.com

XIOC detected Domain: clients2.google.com

extracted_from_files

IP
detected IP: ::

XIOC detected IP: ::

extracted_from_files

Domain
detected Domain: www.browsersolutions.no

XIOC detected Domain: www.browsersolutions.no

extracted_from_files

Other
detected Email: [email protected]

XIOC detected Email: [email protected]

extracted_from_files

Domain
detected Domain: k5a.io

XIOC detected Domain: k5a.io

extracted_from_files

Domain
detected Domain: userreport.com

XIOC detected Domain: userreport.com

extracted_from_files

Domain
detected Domain: parsely.com

XIOC detected Domain: parsely.com

extracted_from_files

Domain
detected Domain: 360yield.com

XIOC detected Domain: 360yield.com

extracted_from_files

Domain
detected Domain: adsby.bidtheatre.com

XIOC detected Domain: adsby.bidtheatre.com

extracted_from_files

Domain
detected Domain: google.com

XIOC detected Domain: google.com

extracted_from_files

URL
detected URL: https://[0-9a-z]*.permutive.com/[0-9a-z

XIOC detected URL: https://[0-9a-z]*.permutive.com/[0-9a-z

extracted_from_files

Domain
detected Domain: facebook.com

XIOC detected Domain: facebook.com

extracted_from_files

Domain
detected Domain: google-analytics.com

XIOC detected Domain: google-analytics.com

extracted_from_files

Domain
detected Domain: doubleclick.net

XIOC detected Domain: doubleclick.net

extracted_from_files

Domain
detected Domain: linkedin.com

XIOC detected Domain: linkedin.com

extracted_from_files

Domain
detected Domain: e.clarity.ms

XIOC detected Domain: e.clarity.ms

extracted_from_files

Domain
detected Domain: static.trafficjunky.com

XIOC detected Domain: static.trafficjunky.com

extracted_from_files

Domain
detected Domain: analytics.tiktok.com

XIOC detected Domain: analytics.tiktok.com

extracted_from_files

Domain
detected Domain: www.facebook.com

XIOC detected Domain: www.facebook.com

extracted_from_files

Domain
detected Domain: snap.licdn.com

XIOC detected Domain: snap.licdn.com

extracted_from_files

Domain
detected Domain: sb.scorecardresearch.com

XIOC detected Domain: sb.scorecardresearch.com

extracted_from_files

Domain
detected Domain: ping.chartbeat.net

XIOC detected Domain: ping.chartbeat.net

extracted_from_files

Domain
detected Domain: logx.optimizely.com

XIOC detected Domain: logx.optimizely.com

extracted_from_files

Domain
detected Domain: tags.tiqcdn.com

XIOC detected Domain: tags.tiqcdn.com

extracted_from_files

Domain
detected Domain: fresnel.vimeocdn.com

XIOC detected Domain: fresnel.vimeocdn.com

extracted_from_files

Domain
detected Domain: amazon-adsystem.com

XIOC detected Domain: amazon-adsystem.com

extracted_from_files

Domain
detected Domain: amazon.com

XIOC detected Domain: amazon.com

extracted_from_files

Domain
detected Domain: com.amazon.csm.csa.prod

XIOC detected Domain: com.amazon.csm.csa.prod

extracted_from_files

Domain
detected Domain: api.permutive.com

XIOC detected Domain: api.permutive.com

extracted_from_files

Domain
detected Domain: byteoversea.com

XIOC detected Domain: byteoversea.com

extracted_from_files

Domain
detected Domain: www.linkedin.com

XIOC detected Domain: www.linkedin.com

extracted_from_files

Domain
detected Domain: www.google-analytics.com

XIOC detected Domain: www.google-analytics.com

extracted_from_files

Domain
detected Domain: connect.facebook.net

XIOC detected Domain: connect.facebook.net

extracted_from_files

Domain
detected Domain: smartadserver.com

XIOC detected Domain: smartadserver.com

extracted_from_files

Domain
detected Domain: adnuntius.delivery

XIOC detected Domain: adnuntius.delivery

extracted_from_files

Domain
detected Domain: adgrx.com

XIOC detected Domain: adgrx.com

extracted_from_files

Domain
detected Domain: t.co

XIOC detected Domain: t.co

extracted_from_files

Domain
detected Domain: googlesyndication.com

XIOC detected Domain: googlesyndication.com

extracted_from_files

Domain
detected Domain: lp4.io

XIOC detected Domain: lp4.io

extracted_from_files

URL
detected URL: https://logx.optimizely.com/v1/events

XIOC detected URL: https://logx.optimizely.com/v1/events

extracted_from_files

URL
detected URL: https://[0-9a-z]*.taboola.com/[0-9a-z]*/log

XIOC detected URL: https://[0-9a-z]*.taboola.com/[0-9a-z]*/log

extracted_from_files

URL
detected URL: https://(play

XIOC detected URL: https://(play

extracted_from_files

URL
detected URL: https://www.googletag(services

XIOC detected URL: https://www.googletag(services

extracted_from_files

URL
detected URL: https://ping.chartbeat.net/ping

XIOC detected URL: https://ping.chartbeat.net/ping

extracted_from_files

URL
detected URL: https://collector.brandmetrics.com

XIOC detected URL: https://collector.brandmetrics.com

extracted_from_files

URL
detected URL: https://fresnel.vimeocdn.com/add/player

XIOC detected URL: https://fresnel.vimeocdn.com/add/player

extracted_from_files

URL
detected URL: https://www.browsersolutions.no/privacy_policy.html

XIOC detected URL: https://www.browsersolutions.no/privacy_policy.html

extracted_from_files

URL
detected URL: https://github.com/browsersolutions/URL-Tracker-Redactor_for_Chrome

XIOC detected URL: https://github.com/browsersolutions/URL-Tracker-Redactor_for_Chrome

extracted_from_files

URL
detected URL: https://clients2.google.com/service/update2/crx

XIOC detected URL: https://clients2.google.com/service/update2/crx

extracted_from_files

Domain
detected Domain: github.com

XIOC detected Domain: github.com

extracted_from_files

Security Analysis Summary

Security Analysis Overview

URL Tracker Redactor is a Chrome Web Store extension published by [email protected]. Version 1.0.5 has been analyzed by the Risky Plugins security platform, receiving a risk score of 40.16/100 (MEDIUM risk) based on 93 security findings.

Risk Assessment

This extension presents moderate security risk. Several findings were detected that may warrant attention. Users should carefully review the permissions and findings before installation.

Findings Breakdown

  • High: 18 finding(s)
  • Medium: 75 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

URL Tracker Redactor is published by [email protected] on the Chrome Web Store marketplace. The extension has approximately 3 users.

Recommendation

Exercise caution with this extension. Review the detailed findings and ensure the requested permissions align with the extension's stated functionality before installation.

Frequently Asked Questions