Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Adblock Ad Blocker Pro

dgjbaljgolmlcmmklmmeafecikidmjpi
Risk Score
5.06
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Adblock
Installs 400,000
Rating 4.3
Last updated 2026-03-25 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer adbloxteam@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing without scoping to this extension — worst-case privacy tier.
  • Developer email is free webmail (gmail) with no verified dev name; adblox.org domain not domain-age verified.
  • 12 external JS hosts in operator fingerprint including bit.ly (affiliate/cloaking) and Yandex properties — unexpected for an adblock extension.
  • No CSP on MV3 extension; function_constructor and obfuscated identifier patterns in scriptlet files raise code-quality concern.
  • Broad host access (*://*/*) paired with webRequest and scripting gives full page read/modify capability on every site.

Evidence

  • free_webmail_dev_no_name store developer_email=adbloxteam@gmail.com, developer_name empty — free webmail with no verified business identity.
  • privacy_policy_admits_collection_and_sharing_unscoped api privacy_policy_classification: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • affiliate_hit_bit_ly crx threat_intel.affiliate_hits: bit.ly listed as affiliate/cloaking redirector in extension's external host set.
  • broad_external_host_fingerprint crx 12 external hosts including 360.yandex., yastatic.net, ya.ru, neonime.net — unusual reach for adblock tool.
  • no_csp_mv3 manifest content_security_policy=null; MV3 strict default applies but no explicit CSP declared.
  • function_constructor_and_obfuscation crx function_constructor in service_worker.js, popup.js, options.js; _0xABCD obfuscated identifiers in multiple scriptlet files.
  • verified_publisher_featured store verified_publisher=true, is_featured_by_google=true — provides partial reputation offset but no cap triggers (fresh, no CVEs).
  • broad_host_plus_scripting_plus_webrequest manifest host_permissions *://*/* + scripting + webRequest — full page read/modify on all sites; justified-broad discount applied for Adblock category.

Permissions Breakdown

  • activeTab low Grants access to current tab only on user gesture; low blast radius.
  • declarativeNetRequest medium Core ad-blocking mechanism; appropriate for category but can block/redirect network requests.
  • webRequest high Observes all network requests across all URLs; high surveillance capability.
  • scripting high Can inject JS into any page matched by host_permissions (*://*/*).
  • storage low Local data persistence only; no cross-origin capability.
  • *://*/* high Broad host access paired with scripting and webRequest — full page reach.

Pillar Scores

Permissions5.50
Reputation5.50
Network4.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00

Scoring History

v3.6 5.06 Medium review 2026-06-16
v3.4-rev 4.83 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:27
Listing SHA 3335a513d44f…
Force block — not fired
Score recovered no
Elapsed 31.3s