Chrome Web Store
5Versions
2Code reviewed

Caution required

Suspicious in code review

Our reviewer found behaviour consistent with malware, but not enough to confirm it. Treat this extension as untrusted until it has been re-reviewed.

What our analysis found

Page Auto Refresh, used by 1,000 people, is rated caution by Extension Auditor. Our code review reported 2 findings (2 medium), led by tracking. Its permissions mean it can inject scripts into pages.

Key findings

  • medium· tracking —On install, and on every update while the version string compares below 6 (the current line is 2.1, so this fires on each update), the extension opens a tab at a hardcoded third-party host that is neither the publisher's website (top.rodeo) nor its declared privacy-policy host (cloudapi.stream), reporting the installation keyed by. The listing declares no data collection at all, so an beacon to an unrelated. host is undisclosed and outside the extension's stated auto-refresh purpose.
  • medium· other —The extension is a repackaged copy of a third-party product — the ksoft/ copyright header is still present at:1 and:1, the internal product name throughout the UI is "Easy Auto Refresh", and the bundled icons are easy-auto-refresh-*.png — yet it is listed as "Page Auto Refresh" by an unrelated publisher with the licensing, purchase (:683) and notification-asset (:118) endpoints repointed to cloudapi.stream. Counterfeiting another vendor's extension and redirecting its paid registration flow to the repackager's own server monetizes users under a false identity, and it places an auto-updating extension with all-sites host permissions on infrastructure the publisher controls but does not disclose as such.

This is a verbatim repackage of ksoft/ 's "Easy Auto Refresh" — the upstream copyright header survives at:1 and:1, the titles still read "Easy Auto Refresh" (:109, 210, 311; modal), and the manifest still ships easy-auto-refresh-*.png icons — relisted as "Page Auto Refresh" with the original vendor's monetization rewired to cloudapi.stream (:10,:118,:683) and an beacon opening id> (:37-45), a domain matching neither the publisher site (top.rodeo) nor its privacy-policy host. Reading every script, I found no exfiltration, no remote code loading and no server-controlled channel into storage: every option written by #kiZQS comes from popup form inputs, the only outbound call is a license-code POST (:40-54), is pure date formatting, and are the genuine upstream logic. Corroborating the ML score: the 0.80 verdict, malicious sibling extensions, the cloudapi.stream IoC tag from the 108-extension campaign, and flagged peers in the permhash cluster; contradicting it: chrome-stats likelihood with a trusted-publisher badge, and code that in this version does exactly what the listing describes. cloudapi.stream is formally first-party under the disclosure rule (it is the listing's own privacy-policy host), so I do not log it as exfiltration — the concern is a counterfeit clone sitting on campaign-linked infrastructure with an update channel that could turn malicious, which is why this is suspicious rather than malicious. Hygiene notes not logged as findings:: injects server-supplied text into popup innerHTML (MV3 extension-page CSP blocks inline script),:16 passes a user-typed "document." string to setTimeout (implicit eval, but only from local popup input), keepAlive() injects a connect stub into all tabs, and browsingData.removeCache is gated on the isCache option. The XOR-7 String.fromCharCode at:60 /:59 masks a license flag, not a payload, so it is not obfuscation; the 22 innerHTML hits are popup status labels and one static-string modal.

Page Auto Refresh

Page Auto Refresh Chrome extension security report

ID: lnajjhohknhgemncbaomjjjpmpdigedg

Supported Languages

🇸🇦Arabic
🇧🇬Bulgarian
🇨🇳Chinese (Simplified)
🇹🇼Chinese (Traditional)
🇭🇷Croatian
🇨🇿Czech
🇩🇰Danish
🇳🇱Dutch
🇺🇸English
🇪🇪Estonian
🇵🇭Filipino
🇫🇮Finnish
🇫🇷French
🇩🇪German
🇬🇷Greek
🇮🇱Hebrew
🇭🇺Hungarian
🇮🇩Indonesian
🇮🇹Italian
🇯🇵Japanese
🇰🇷Korean
🇱🇻Latvian
🇱🇹Lithuanian
🇳🇴Norwegian
🇮🇷Persian
🇵🇱Polish
🇷🇴Romanian
🇷🇺Russian
🇷🇸Serbian
🇸🇰Slovak
🇸🇮Slovenian
🇪🇸Spanish
🇸🇪Swedish
🇹🇭Thai
🇹🇷Turkish
🇺🇦Ukrainian

Extension Info & Metadata

Status
Active
Version
2.1
Size
0.09 MB
Rating
4.3/5
Reviews
6
Users
1,000
Type
Extension
Updated
Jul 29, 2026
Category
Tools
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes
This publisherTrack record
71extensions
41 no longer listed

Publisher Contextual Analysis

Trusted
Author
https://top.rodeo/
Country
DE
Address
Ringelsweide 28 Düsseldorf 40223 DE
Website
Visit
Extensions
71
Active
30
Obsolete
41
Listed
71
Unlisted
0
Users
12,358

Screenshots & videos

Screenshot 1

Install growth

Item
Type
Severity
Description
scripting
Permission
Critical
This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to.
browsingData
Permission
High
This permission clears browsing data, history, and redis. Rated High because it can destroy evidence of malicious activity, clear security logs, and modify browser state.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 10% increase: Early script execution enables pre-emptive content manipulation
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
http://*/
Host
Medium
Host permission — access limited to this URL pattern.
https://*/
Host
Medium
Host permission — access limited to this URL pattern.
Early Content Script Execution
Risk Factor
Medium
This extension runs content scripts at document_start.
notifications
Permission
Low
This permission displays system notifications. Rated Low because it can only show user-visible notifications without accessing system data.
alarms
Permission
Low
This permission schedules periodic tasks. Rated Low because it can only trigger events at specified times without access to sensitive data.
  • 2 medium

The file, code excerpt and explanation behind each finding are part of the full report. No conclusion has been withheld — only the evidence. The verdict above already reflects everything found here.

Gain full insight into all external connections.

Upgrade for full visibility.

About this extension

Page Auto Refresh: Auto-refresh and auto-reload pages after any number of seconds

Read the publisher’s full description

Auto-Refresh and Auto-Reload Pages After a Set Time Interval Automatically refresh web pages after a specified number of seconds. Key Features: - Refresh pages at customizable intervals. - Set unique refresh delays for each page or tab. - Save preferences individually for each web page URL. - Retain your web page’s scroll position across reloads. - Simply input the number of seconds between reloads and click "Start." You can set different refresh intervals per tab. Preferences are saved automatically based on the web page’s URL. The countdown pauses while you're typing. To stop auto-refresh, simply click "Stop." Premium Features (Unlock with Page Auto Refresh Registration): - Save settings per individual web page URL or website domain. - Enable random countdown intervals. - Schedule refreshes for specific times of the day. - Reload all open tabs within the window simultaneously. - Automatically click buttons, links, or elements on the page. - Navigate to a URL from a predefined list at each refresh interval. - Receive notifications and play sounds when specific text is found on the page. - Display the time of the last and next scheduled refresh. - Option to clear browser cache. - Access to future updates and feature enhancements. ----------- Let me know if you'd like to adjust anything further!

User reviews

Extension files

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.

URLs
5

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

No URLs found
No IP addresses found

Gain full insight into all external connections.

Upgrade for full visibility.

Version
Size
Verdict
Findings
Permhash
2.1
Latest
0.09 MBCaution0
aea4adb6836c190bce0a37f5a25e4fb913b6f70f8ece59f1c47344da7afff07a
1.7
0.08 MBCaution0
aea4adb6836c190bce0a37f5a25e4fb913b6f70f8ece59f1c47344da7afff07a
1.6
0.09 MBCaution—
aea4adb6836c190bce0a37f5a25e4fb913b6f70f8ece59f1c47344da7afff07a
1.4
0.10 MBCaution—
aea4adb6836c190bce0a37f5a25e4fb913b6f70f8ece59f1c47344da7afff07a
1.5
0.10 MBCaution—
aea4adb6836c190bce0a37f5a25e4fb913b6f70f8ece59f1c47344da7afff07a
Showing 1 to 5 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files detected

No comparable text files found between these versions.

Gain full insight into all external connections.

Upgrade for full visibility.

More from https://top.rodeo/

Popular in Tools