Real Valladolid Club De Fútbol

Real Valladolid Club De Fútbol

ID: opjmhbemagooegecfaakiihaoooljbhi

Extension Info & Metadata

Status
Active
Version
4.1.1
Size
2.91 MB
Rating
0.0/5
Reviews
0
Users
5
Type
Extension
Updated
Jun 13, 2026
Category
Tools
Price
Free
Featured
No
Visibility
Unlisted
Mature
No
By Google
No
Trusted
Yes

Publisher Contextual Analysis

Trusted
Author
brandTURBOView Profile
Country
DE
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
Yes
Mailbox exists
Yes
Address
Straßburger Str. 55 Berlin 10405 DE
Website
Visit
Total Extensions
99
Active
50
Obsolete
49
Listed
37
Unlisted
62
Total Users
39,534
Screenshot 1
Screenshot 2
Screenshot 3

Contenido exclusivo del del Real Valladolid Club de fútbol.

Contenido creado exclusivamente para el google store. Los aficionados podrán personalizar su escritorio con contenido especial del Real Valladolid. Además podrán estar al tanto de todas las noticias y tener acceso directo a las secciones principales del club. Descarga esta extensión para ser el mayor fanático del club y contar con nuevos elementos exclusivos. Se trata de una extensión empresarial de marca blanca para Real Valladolid CF.

Item
Type
Severity
Description
topSites
Permission
High
This permission accesses the list of most visited websites. Rated High because it can reveal browsing patterns, identify frequently accessed service, and gather user behavior data.
favicon
Permission
Low
This permission accesses website favicon images. Rated Low because it only retrieves publicly visible website icons.
search
Permission
Low
This permission accesses search functionality. Rated Low because it only interacts with the browser's search feature without accessing search history.

All user searches are routed through m.instantsearch.net with a persistent revenue-tracking tag (rtag=rlvll, rsrc=e). The 'search' permission in the bundled manifest enables this browser-level search override. This constitutes undisclosed commercial search monetization to a third-party platform — the CWS listing describes only branded fan content with no mention of search redirection.

startpage.js (Line 4671)
e.n = 1, fetch(i, {  mode: "cors",  credentials: "include",  redirect: "follow",  method: "GET"})// where i = (0, u.Gy)("https://m.instantsearch.net/themes", d(d({},//   r), {}, {//   id: o,//   rtag: s.XZ,//   rsrc: "e",//   jsv: s.Y3// }))

The bundled manifest (MV3) declares 'favicon' and 'search' as required permissions while the published CWS listing shows MV2 with only 'topSites' required (favicon as optional via chrome://favicon/, search absent). The 'search' permission specifically enables overriding the browser's search engine — the mechanism that powers the undisclosed search monetization through instantsearch.net. This version-to-listing mismatch suggests the publisher updated the bundle without updating the CWS listing metadata.

manifest.json (Line 4)
{  "manifest_version": 3,  "permissions": [    "topSites",    "favicon",    "search"  ],  "optional_permissions": [    "history",    "bookmarks"  ]}

The extension fetches its configuration from m.instantsearch.net, a third-party commercial search platform, passing user-specific tracking parameters including rtag='rlvll' and jsv (JS version) with credentials included. This is not first-party (publisher domain is brandturbo.vip / realvalladolid.es) and is not disclosed in the CWS data-collection declaration. The 'credentials: include' flag means any cookies the user has at instantsearch.net are transmitted.

startpage.js (Line 21116)
v = (0, qt.Gy)("https://m.instantsearch.net/config", Zt(Zt(    Zt({}, c), l), {}, {    id: p,    rtag: y,    rsrc: h,    draft: m,    jsv: Ke.Y3  })), t.n = 2, (0, qt.u9)(v, {      mode: "cors",      credentials: "include",      redirect: "follow",      method: "GET"    }

User interaction events (history clicks, settings changes, background rotations) are sent to the searchturbo analytics endpoint via navigator.sendBeacon with a persistent user-tracking tag (rtag) and session timing. The destination is the searchturbo platform, a third party unrelated to Real Valladolid CF, and this data collection is not disclosed in the CWS listing (declared: none).

startpage.js (Line 5556)
navigator.sendBeacon ? n(navigator.sendBeacon(e, JSON.stringify(t))) : n(!1)// payload built above:var i = h(h({}, n), {}, {  t: e.type,  val: e.value,  rtag: t.rtag,  rsrc: "e",  jsv: u.Y3,  te: Math.floor((Date.now() - b) / 1e3)});

By severity

Critical0
High2
Medium2
Low0

Versions scanned

Showing 1 of 2 scanned versions with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
4.1.14

Files with findings

2 distinct paths — top paths by unique finding count:

  • startpage.js3
  • manifest.json1
S.No.
Category
Severity
File
Summary
Found in Version
1Other
high
manifest.json (line 4)The bundled manifest (MV3) declares 'favicon' and 'search' as required permissions while the published CWS listing shows MV2 with only 'topSites' required (favicon as optional via chrome://favicon/, search absent). Th…
2Tracking
high
startpage.js (line 4671)All user searches are routed through m.instantsearch.net with a persistent revenue-tracking tag (rtag=rlvll, rsrc=e). The 'search' permission in the bundled manifest enables this browser-level search override. This co…
3Tracking
medium
startpage.js (line 21116)The extension fetches its configuration from m.instantsearch.net, a third-party commercial search platform, passing user-specific tracking parameters including rtag='rlvll' and jsv (JS version) with credentials includ…
4Tracking
medium
startpage.js (line 5556)User interaction events (history clicks, settings changes, background rotations) are sent to the searchturbo analytics endpoint via navigator.sendBeacon with a persistent user-tracking tag (rtag) and session timing. T…
URLs
89
IPv4
13
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

m.instantsearch.net/suggesthttps://m.instantsearch.net/suggest?fmt=rch2&rtag=
myaccount.google.com-https://myaccount.google.com
google.com-https://google.com
maps.google.com-https://maps.google.com
www.youtube.com-https://www.youtube.com
play.google.com-https://play.google.com
mail.google.com-https://mail.google.com
contacts.google.com-https://contacts.google.com
drive.google.com-https://drive.google.com
calendar.google.com-https://calendar.google.com
Showing 1 to 10 of 90 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.

1.22.17.37
IPv4
-
18.18.43.29
IPv4
-
28.11.53.29
IPv4
-
18.19.43.3
IPv4
-
17.14.37.23
IPv4
-
31.1.59.16
IPv4
-
28.22.59.5
IPv4
-
17.18.42.29
IPv4
-
24.1.46.24
IPv4
-
19.22.45.37
IPv4
-
17.12.36.21
IPv4
-
39.12.73.2
IPv4
-
35.28.72.62
IPv4
-
Showing 1 to 13 of 20 rows
Rows per page:
Version
Size
Is Malicious
Findings
Permhash
4.1.1
Latest
2.91 MB
Malicious
4
3.2.1
2.93 MB
Malicious
Showing 1 to 2 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.