Pop up blocker for Chrome™ - Poper Blocker
bkkbcggnhapdmkeljlodobbkopceiche
Risk Score
2.98
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- eval() of variable in twitchStreamAdBlockInjectScript.js — code execution risk if workerString is attacker-controlled.
- new Function() constructor in service-worker.js — dynamic code execution, though appears in bundled minified boilerplate.
- broad host permission *://*/* + scripting allows content injection on every site visited.
- webRequest over all URLs — full network observation capability across all browsing.
- Privacy policy discloses third-party data sharing; scoped but sharing acknowledged.
Evidence
- verified_publisher + featured store Extension is verified publisher and featured by Google; strong legitimacy signal.
- eval_user_input crx eval(workerString) in twitchStreamAdBlockInjectScript.js — variable eval in injected worker context.
- function_constructor crx new Function('return this') in service-worker.js — likely bundler boilerplate but flagged.
- broad_host_permissions manifest host_permissions: *://*/* plus scripting permission — full cross-site injection capability.
- privacy_policy_third_party store Privacy policy fetched; scoped to extension, data_collection=true, third_party_sharing=true, retention=true.
- js_external_hosts crx 12 external hosts including analytics.poperblocker.com and app.pbapi.xyz; all appear dev-controlled or informational.
- no_bad_hosts_no_affiliates api threat_intel shows zero bad_host_hits, affiliate_hits, and monetization_hits.
- recently_updated_mv3 store Updated June 2026, 0 months stale, MV3, CSP present — strong maintenance posture.
Permissions Breakdown
- storage low Stores settings locally; minimal risk.
- activeTab low Scoped to user-activated tab only.
- webRequest high Can observe and intercept all network requests; core to ad/popup blocking.
- declarativeNetRequest medium Rule-based network blocking; expected for adblocker category.
- declarativeNetRequestFeedback low Read-only feedback on DNR rules; low risk.
- contextMenus low Adds right-click menu items; low risk.
- scripting medium Can inject scripts into pages; paired with <all_urls> host permission.
- webNavigation medium Observes navigation events across all tabs; standard for blockers.
- alarms low Schedules background tasks; minimal risk.
- *://*/* high Broad host access across all sites; expected for popup blocker but high surface area.
Pillar Scores
Permissions4.50
Reputation2.00
Network2.00
Webstore2.50
Maintenance0.00
Privacy1.00
Code Quality5.50
CVE Exposure0.00
Scoring History
| fsssiedxm sssiedx | 2.14 | Low | review | 2026-08-24 |
| fsssiedxm | 2.89 | Low | review | 2026-08-24 |
| sssieddrubricxsx | 3.05 | Low | review | 2026-08-24 |
| v3.6 | 2.98 | Low | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:20
Listing SHA
e5f378be2270…
Force block
— not fired
Score recovered
no
Elapsed
25.5s