Analytics & Ad Blocker: Open Source Privacy Firewall
fapldghopmonkbgaaiinpeopokpkhbmk
Risk Score
5.45
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — does not scope to this extension, yet admits data collection and third-party sharing (Privacy = 10.0).
- Developer uses free Gmail address with no developer name and no business domain; low accountability.
- Content script injected on <all_urls> combined with cookies permission; high reach on every site.
- install_url_hijack: onInstalled opens options page, minor but flags engagement-optimization intent.
- small_install_high_perm anomaly flagged: 839 installs with high-tier permissions is a tail-attack-surface indicator.
Evidence
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar 10.0.
- developer_identity_weak store developer_name empty, email is free Gmail (fintab.help@gmail.com); no verified publisher badge.
- content_scripts_all_urls manifest content_scripts_matches=[<all_urls>] injects into every page; no host_permissions but reach is broad.
- cookies_permission manifest cookies permission declared; combined with all_urls content script raises read risk.
- function_constructor crx new Function() in options.bundle.js; potential code execution from string input.
- install_url_hijack crx onInstalled opens options.html?tab=about; low-severity engagement pattern.
- install_perm_anomaly api small_install_high_perm=true; 839 installs with high-tier permissions flagged.
- external_hosts crx Contacts safebrowsing.googleapis.com and stuk.github.io; stuk.github.io is a third-party JS host.
Permissions Breakdown
- storage low Local config/settings storage; low risk.
- activeTab medium Access to current tab on user action; limited scope.
- declarativeNetRequest medium Network request blocking/modifying; appropriate for Adblock category.
- declarativeNetRequestFeedback medium Read match feedback on blocked requests; minor information exposure.
- cookies high Cookie read/write; no broad host_permissions but still sensitive.
- content_scripts:<all_urls> high Script injected into every page; high reach even without host_permissions.
Pillar Scores
Permissions5.50
Reputation7.00
Network3.00
Webstore5.50
Maintenance1.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:32
Listing SHA
ffd9b225e3e1…
Force block
— not fired
Score recovered
no
Elapsed
23.5s