Urban AdBlocker
feflcgofneboehfdeebcfglbodaceghj
Risk Score
2.73
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- webRequest + <all_urls> + scripting gives full traffic interception capability on every site visited.
- Explicit redirect API host_permission (api-pro.urban-vpn.com/rest/v1/redirect/) could enable traffic manipulation.
- Remote config endpoint (config-toolbar.urban-vpn.com) allows server-side rule changes without extension update.
- new Function() constructor found in content and service worker scripts; low obfuscation but dynamic eval risk.
- No CSP declared (MV3 default applies); combined with function_constructor findings slightly elevates code risk.
Evidence
- webRequest + <all_urls> manifest webRequest permission combined with <all_urls> host access gives full network interception on every page.
- redirect API host_permission manifest api-pro.urban-vpn.com/rest/v1/redirect/* explicitly declared; enables server-directed traffic redirection.
- remote config endpoint manifest config-toolbar.urban-vpn.com in host_permissions allows server to push config/filter changes dynamically.
- function_constructor x2 crx new Function() found in content script and service worker; one is webpack boilerplate, one evaluates expressions.
- is_featured_by_google store Google Featured badge reduces reputation risk; not verified publisher but featured.
- privacy policy store Scoped policy with data_collection, retention, third_party_sharing all disclosed; adequate.
- no CVEs, no bad hosts, no monetization hits api threat_intel and cve_findings_raw both empty; no known malicious infrastructure detected.
- justified-broad-permission discount applied manifest Category=Adblock; broad host access + webRequest match stated function per rubric discount.
Permissions Breakdown
- tabs medium Access to tab URLs and metadata; medium risk for an adblocker needing page context.
- webNavigation medium Tracks navigation events across all pages; used legitimately for filter timing.
- storage low Stores filter lists and user preferences locally.
- alarms low Schedules filter-list updates; low risk.
- scripting medium Can inject scripts into pages; paired with <all_urls> this is broad capability.
- webRequest high Intercepts all network requests; core to ad blocking but also enables surveillance.
- declarativeNetRequest medium Declarative blocking; safer than webRequestBlocking but still broad.
- <all_urls> high Host access to every site visited; justified for adblocker but high capability.
- https://api-pro.urban-vpn.com/rest/v1/redirect/* high Explicit redirect API endpoint in host_permissions raises concern about traffic manipulation.
- https://authentication.urban-vpn.com/* medium Auth backend access; acceptable for account-linked product.
- https://anti-phishing-protection-toolbar.urban-vpn.com/* medium Contacts anti-phishing backend; plausible for security feature.
- https://config-toolbar.urban-vpn.com/* medium Remote config endpoint; could push rule changes without extension update.
Pillar Scores
Permissions5.50
Reputation3.50
Network2.00
Webstore1.00
Maintenance0.00
Privacy0.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 07:45
Listing SHA
c4d8fb91ef82…
Force block
— not fired
Score recovered
no
Elapsed
—