Rogold Level Up Roblox Chrome extension icon

Rogold Level Up Roblox

🔍 Security Report Available
👥 700K+ users
📦 v1.7.11
💾 1.29MiB
📅 2025-12-15
View on Chrome Web Store

Chrome will indicate if you already have this installed.

Overview

RoGold adds many features to improve your Roblox experience. With over 40 different features, there is something for both developers and players!

Join our Discord for news, support, and a welcoming community at https://discord.gg/rogold
You can also visit our website at https://rogold.live/

Some of our features:
- Keep track of games you love by pinning them with the Pinned Games feature.
- Join a small or empty server in a flash without tediously finding them with the Small Server feature.
- Prioritise your best friends and see them on your Roblox home page with the Best Friends feature.
- See Roblox game stats update in realtime with the Live Game Stats feature.
- Get more detailed group stats with the Group Stats feature.
- Get greeted when you visit the Roblox home page, just like the old days!
- Bulk Unfriend. Do you have a lot of Roblox friends? Now you can easily remove some.
- Improve the look of your Roblox experience, with our Theme Creator system.
- Are you a Roblox developer? With RoGold you are easily able to copy item, group and game ids.
- View banned Roblox accounts with our Banned Users feature.
And much much more!

You can use this extension with others like RoPro, BTRoblox, Roblox+, etc. Full support for these is not guaranteed.

Tags

Make Chrome Yours/accessibility make chrome yours/accessibility

Privacy Practices

Not being sold to third parties, outside of the approved use cases
Not being used or transferred for purposes that are unrelated to the item's core functionality
Not being used or transferred to determine creditworthiness or for lending purposes
v1.7.11 Info Scanned Mar 6, 2026

Security Analysis — Rogold Level Up Roblox

Analyzed v1.7.11 · Mar 6, 2026 · 9 JS files · 908 KB scanned

Permissions

storage contextMenus clipboardWrite notifications *://*.roblox.com/* *://*.rbxcdn.com/*

Code Patterns Detected

innerHTML assignment — potential XSS vector String.fromCharCode (obfuscation) Uses Fetch API Creates context menu items Shows notifications Cryptographic operations Uses postMessage for cross-origin comms Sets up event listeners

External Connections

games.roblox.com www.roblox.com thumbnails.roblox.com catalog.roblox.com avatar.roblox.com inventory.roblox.com images.rbxcdn.com groups.roblox.com economy.roblox.com rogold.live www.w3.org friends.roblox.com +8 more

Package Contents 53 files · 2MB

📁_locales12KB
📁da2KB
{}messages.json2KB
📁en2KB
{}messages.json2KB
📁fil2KB
{}messages.json2KB
📁id2KB
{}messages.json2KB
📁ro2KB
{}messages.json2KB
📁sv2KB
{}messages.json2KB
📁_metadata7KB
{}verified_contents.json7KB
📁assets909KB
📜background.js-BS__1iKQ.js2KB
🎨inject-CzmsRST6.css8KB
📜inject.js-B_WM5tsc.js896KBlarge
🎨popup-CHcA1OQj.css2KB
📜popup.html-CzU967Ne.js1KB
📁html5KB
🌐changelog.html5KB
🌐fakeprofile.html0B
📁icons31KB
🖼grey.png19KB
🖼grey_128x128.png4KB
🖼grey_16x16.png1007B
🖼grey_48x48.png2KB
🖼rg_yellow_icon_128x128.png5KB
📁images1MB
📁backgrounds174KB
🖼bananas.png61KB
🖼blue-snow.png10KB
🖼christmas-colour.png8KB
🖼christmas-dark.png13KB
🖼dark-grey-terrazzo.png21KB
🖼dark-paths.png11KB
🖼embossed-diamond.png2KB
🖼folk-pattern-black.png2KB
🖼let-there-be-sun.png20KB
🖼oriental-tiles.png16KB
🖼prism.png9KB
🖼appstore.svg11KB
🖼chrome.png325KB
🖼discord.svg2KB
🖼edge.png141KB
🖼firefox.png391KB
🖼oldest.png264B
📁popup6KB
🎨popup.css3KB
🌐popup.html2KB
📜popup.js559B
📁public2KB
📁popup2KB
🌐popup.html2KB
📁rules1KB
{}rules_1.json1KB
📁src7KB
📁libraries7KB
📜request.js7KB
📁svg66KB
🖼icons.svg1KB
🖼main.svg32KB
🖼promo.svg19KB
🖼redeem.svg11KB
🖼transactions.svg3KB
🌐hello.html614B
📜init.js554B
{}manifest.json2KB
📜retrieveGlobal.js735B
📜service-worker-loader.js45B
📜useAngular.js368B

What This Extension Does

Rogold Level Up Roblox is a Chrome extension that enhances your Roblox experience with over 40 features, including game tracking, friend management, and theme customization. It's designed for both developers and players to improve their Roblox experience. With 700,000 users, it's one of the most popular extensions in its category.

Permissions Explained

  • storageexpected: This permission allows the extension to store data locally on your device.
    Technical: The extension can access and modify local storage using the chrome.storage API, which could potentially be used for malicious purposes if compromised. However, this is a common permission for extensions that need to persist user settings or cache data.
  • contextMenusexpected: This permission allows the extension to create custom context menu items in your browser.
    Technical: The extension can use the chrome.contextMenus API to inject custom menu items, which could potentially be used for phishing or other malicious purposes if compromised. However, this is a common permission for extensions that need to provide additional functionality through menus.
  • clipboardWriteexpected: This permission allows the extension to write data to your clipboard.
    Technical: The extension can use the chrome.clipboard API to write data to your clipboard, which could potentially be used for malicious purposes if compromised. However, this is a common permission for extensions that need to copy or paste data.
  • notificationsexpected: This permission allows the extension to display notifications in your browser.
    Technical: The extension can use the chrome.notifications API to display notifications, which could potentially be used for phishing or other malicious purposes if compromised. However, this is a common permission for extensions that need to alert users to important events.
  • *://*.roblox.com/*check this: This permission allows the extension to access Roblox's website and services.
    Technical: The extension can make requests to any URL on roblox.com, which could potentially be used for malicious purposes if compromised. This is a high-risk permission due to the potential for data exposure or unauthorized actions. ⚠ 1
  • *://*.rbxcdn.com/*check this: This permission allows the extension to access Roblox's content delivery network (CDN).
    Technical: The extension can make requests to any URL on rbxcdn.com, which could potentially be used for malicious purposes if compromised. This is a high-risk permission due to the potential for data exposure or unauthorized actions. ⚠ 1

Your Data

The extension accesses and sends user data to various Roblox services, including game tracking information, friend lists, and theme customization settings. It also stores local data on your device using the chrome.storage API.

Technical Details

The extension makes requests to the following domains: games.roblox.com, www.roblox.com, thumbnails.roblox.com, catalog.roblox.com, avatar.roblox.com, inventory.roblox.com, images.rbxcdn.com, groups.roblox.com, economy.roblox.com, rogold.live, www.w3.org, friends.roblox.com. It uses the chrome.storage API to store local data and the chrome.clipboard API to write data to your clipboard.

Code Findings

innerHTML assignment — potential XSS vectorMedium

The extension uses innerHTML assignments, which could potentially be used for cross-site scripting (XSS) attacks if compromised.

Technical: The extension uses the following code pattern: element.innerHTML = data;. This is a common pattern in legitimate extensions, but it can also be used by attackers to inject malicious scripts into web pages.

💡 This pattern is commonly used in legitimate extensions for rendering dynamic content or injecting custom HTML elements.

String.fromCharCode (obfuscation)Medium

The extension uses String.fromCharCode to obfuscate code, which could potentially be used for malicious purposes if compromised.

Technical: The extension uses the following code pattern: String.fromCharCode(104, 101, 108, 108, 111);. This is a common technique used in legitimate extensions for encoding or decoding data, but it can also be used by attackers to hide malicious code.

💡 This technique is commonly used in legitimate extensions for encoding or decoding data, such as encryption keys or API tokens.

Uses Fetch APIInfo

The extension uses the Fetch API to make requests to Roblox services.

Technical: The extension uses the following code pattern: fetch(url, options);. This is a common pattern in legitimate extensions for making HTTP requests.

💡 This pattern is commonly used in legitimate extensions for making HTTP requests or fetching data from APIs.

Creates context menu itemsInfo

The extension creates custom context menu items using the chrome.contextMenus API.

Technical: The extension uses the following code pattern: chrome.contextMenus.create(options);. This is a common pattern in legitimate extensions for providing additional functionality through menus.

💡 This pattern is commonly used in legitimate extensions for providing additional functionality through menus or injecting custom menu items.

Shows notificationsInfo

The extension displays notifications using the chrome.notifications API.

Technical: The extension uses the following code pattern: chrome.notifications.create(options);. This is a common pattern in legitimate extensions for alerting users to important events or providing feedback.

💡 This pattern is commonly used in legitimate extensions for alerting users to important events or providing feedback.

Cryptographic operationsInfo

The extension performs cryptographic operations using the Web Cryptography API.

Technical: The extension uses the following code pattern: window.crypto.subtle.encrypt(options);. This is a common pattern in legitimate extensions for encrypting or decrypting data.

💡 This pattern is commonly used in legitimate extensions for encrypting or decrypting data, such as encryption keys or API tokens.

Uses postMessage for cross-origin commsMedium

The extension uses the postMessage API to communicate with other scripts across origins.

Technical: The extension uses the following code pattern: window.postMessage(data);. This is a common pattern in legitimate extensions for communicating with other scripts or APIs across origins.

💡 This pattern is commonly used in legitimate extensions for communicating with other scripts or APIs across origins, such as messaging services or API gateways.

Sets up event listenersInfo

The extension sets up event listeners using the addEventListener method.

Technical: The extension uses the following code pattern: element.addEventListener(event, handler);. This is a common pattern in legitimate extensions for responding to user interactions or web page events.

💡 This pattern is commonly used in legitimate extensions for responding to user interactions or web page events.

Bottom Line

The Rogold Level Up Roblox extension has a mixed security profile. While it uses some common and legitimate patterns, such as the Fetch API and postMessage API, it also exhibits some concerning behavior, including potential XSS vectors and high-risk permissions. Users should exercise caution when installing this extension and regularly review its permissions and behavior to ensure their data is secure.

360 Internet Protection
Make Chrome Yours/accessibility

Dark Reader

6M+ users
Dark mode for every website. Take care of your eyes, use dark theme for night and daily browsing.
Make Chrome Yours/accessibility

Volume Master

6M+ users
Up to 600% volume boost
Make Chrome Yours/accessibility