AdDragon - Ad Blocker, Free VPN and Popup Blocker
fghcafllghpooedjmgghkflnknnlgbia
Risk Score
4.87
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- proxy + webRequest + <all_urls>: full traffic interception capability from a gmail-addressed dev with no scoped privacy policy.
- Privacy policy is Google's own account policy — not scoped to this extension, data_collection=true, third_party_sharing=true.
- Developer uses free Gmail address with no verifiable business domain; no verified publisher badge.
- innerHTML DOM-XSS sink in main JS bundle; CSP uses trusted-types which mitigates but does not eliminate risk.
- Geo-diverse JS hosts (CA/FR/IN/US, 4 countries) and 12 external hosts listed in operator fingerprint for a 3 000-install extension.
Evidence
- proxy+webRequest+<all_urls> manifest proxy, webRequest, webRequestAuthProvider all declared alongside <all_urls> host permission — full traffic interception.
- gmail_developer store developer_email is software.dev.tube+support@gmail.com; free webmail, no verified business domain.
- generic_privacy_policy api Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- dom_sink_innerhtml crx code_findings_raw reports dom_sink_innerhtml_userctrl in assets/index-DKAROU1K.js; DOM-XSS risk.
- geo_diversity crx JS hosts span 4 countries (CA,FR,IN,US); 12 external hosts in operator fingerprint for low-install extension.
- no_verified_publisher store verified_publisher=false, is_featured_by_google=false; no trust anchors.
- csp_trusted_types manifest CSP uses trusted-types + script-src 'self'; mitigates innerHTML risk but policy is self-only, no remote script loading.
- no_cve_findings crx cve_findings_raw is empty; no known-vulnerable bundled libraries detected.
Permissions Breakdown
- tabs medium Can read tab URLs and metadata across all tabs.
- activeTab low Access limited to currently active tab on user gesture.
- proxy high Can intercept and reroute all network traffic — very high capability.
- background low Persistent background execution; standard for VPN/adblock.
- scripting medium Can inject JS into pages; paired with <all_urls> is broad.
- storage low Local data persistence only.
- unlimitedStorage low Extended local storage; low direct risk.
- declarativeNetRequest medium Rule-based request blocking; core adblock function.
- webRequest high Observe all network requests across all URLs.
- webRequestAuthProvider high Can handle HTTP auth credentials — sensitive.
- alarms low Scheduled background tasks; low risk.
- webNavigation medium Observe navigation events across all frames.
- <all_urls> high Broad host access enabling content scripts and requests on every site.
Pillar Scores
Permissions6.30
Reputation6.50
Network3.00
Webstore3.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:33
Listing SHA
6c3dcc8028fd…
Force block
— not fired
Score recovered
no
Elapsed
29.3s