Free simple Adult Blocker with password
fgfoepffhjiinifbddlalpiamnfkdnim
Risk Score
5.43
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits data collection and third-party sharing without scoping to this extension — privacy pillar scores maximum.
- Uninstall URL hijack to adultblocker.org/uninstall and install URL hijack — monetization/tracking signal.
- Content scripts on <all_urls> with DOM-XSS innerHTML sink and no CSP — elevated code risk.
- No developer name listed; verified publisher but 18 months since last update triggers discount cap (invariant 0c).
- Broad host permission https://*/* combined with external JS host (reactjs.org CDN) and no CSP present.
Evidence
- uninstall_url_hijack manifest chrome.runtime.setUninstallURL to https://adultblocker.org/uninstall — 3rd-party redirect on uninstall.
- install_url_hijack manifest onInstalled opens https://adultblocker.org/install — 3rd-party URL on install.
- privacy_policy_scope_extension_false api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — triggers D rule (+10).
- dom_sink_innerhtml_userctrl+no_csp crx innerHTML sink in popup.100f6462.js; csp_present=false triggers FIX B (+2.0 vs +0.5).
- external_js_host_reactjs.org crx js_external_hosts includes reactjs.org — external CDN without CSP enforcement.
- verified_publisher_stale_18mo store Verified publisher but months_since_update=18 triggers invariant 0c: discount capped at -1.0.
- tail_attack_surface api install_perm_anomaly.tail_attack_surface=true: low-install count with high-tier host permissions.
- no_developer_name store developer_name is empty; reputation penalty applied (+1.0).
Permissions Breakdown
- alarms low Scheduled tasks; minimal standalone risk.
- declarativeNetRequest medium Allows blocking/redirecting network requests — core to content-blocking function, but can intercept traffic.
- tabs medium Access to tab URLs and metadata; enables surveillance of browsing activity.
- storage low Local data persistence; low risk in isolation.
- https://*/* high Broad host permission covering all HTTPS sites; paired with content_scripts on <all_urls>.
- content_scripts:<all_urls> high Content scripts injected on every page; combined with DOM-XSS sink finding raises risk.
Pillar Scores
Permissions5.50
Reputation4.00
Network3.50
Webstore6.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:06
Listing SHA
4a6df3eff4a0…
Force block
— not fired
Score recovered
no
Elapsed
—