AI CleanWeb - Ad Blocker & Privacy Shield
fagiajhfckhedbooimfmkapldghpeknc
Risk Score
2.29
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy admits data collection and third-party sharing without retention disclosure.
- No developer name listed; low install count (22) with high permissions raises tail-attack-surface concern.
- Content scripts run on all URLs including reddit.com and twitter.com via js_external_hosts.
- No CSP on MV3 extension with scripting + <all_urls>; adds v2 network penalty.
- small_install_high_perm anomaly: 22 installs with broad host access is suspicious.
Evidence
- small_install_high_perm store Only 22 installs but has <all_urls> + scripting; install_perm_anomaly.small_install_high_perm=true.
- privacy_policy_third_party_sharing api Policy fetched, scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
- no_developer_name store developer_name is empty string; reduces accountability.
- js_external_hosts_broad crx External hosts include reddit.com and twitter.com beyond dev-controlled domains.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening.
- verified_publisher store verified_publisher=true via sales@magentoweb.com; domain resolves, not throwaway.
- no_bad_hosts_no_cves api bad_host_hits=[], cve_findings_raw=[], affiliate_hits=[], monetization_hits=[] — clean threat intel.
- code_quality_clean crx 27 JS files scanned, obfuscation_score=0.0, code_findings_raw empty — no malicious patterns found.
Permissions Breakdown
- declarativeNetRequest medium Intercepts and blocks network requests; core adblock function, medium risk.
- storage low Stores extension settings locally; low impact.
- alarms low Schedules background tasks; low risk on its own.
- scripting medium Can inject scripts into pages; elevated with <all_urls> host access.
- activeTab low Limits script injection to user-activated tab; mitigates scripting scope somewhat.
- <all_urls> high Broad host access enabling content script and declarativeNetRequest on all sites.
Pillar Scores
Permissions4.00
Reputation4.50
Network2.00
Webstore3.50
Maintenance0.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 08:14
Listing SHA
5a3b67a8403d…
Force block
— not fired
Score recovered
no
Elapsed
—