Adblock.mx - Adblock for Chrome
hmaeodbfmgikoddffcfoedogkkiifhfe
Risk Score
5.18
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits data collection and third-party sharing but is not scoped to this extension — scores maximum privacy risk.
- Uninstall URL hijack sends users to adblock.mx on removal; install URL opens 3rd-party page on install.
- Developer email is free Gmail with no developer name listed, reducing accountability.
- contacts www.googleadservices.com externally — ad-tech host unexpected for an adblocker.
- 18 months since last update; borderline stale; invariant 0c limits verified-publisher discount.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL → https://adblock.mx/uninstall/ (+3.0 webstore)
- install_url_hijack crx onInstalled opens https://adblock.mx/install/ (+2.0 webstore)
- privacy_policy_generic_admitting_sharing api scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D)
- js_external_host_ad_tech crx www.googleadservices.com in js_external_hosts — ad-tech domain unexpected for an adblocker.
- developer_email_free_webmail_no_name store adblock.mx.mail@gmail.com; developer_name empty → reputation penalty applied.
- verified_publisher_featured store verified_publisher=true, is_featured_by_google=true; discounts capped at -1.0 (months_since_update==18).
- dom_sink_innerhtml_userctrl crx popup.100f6462.js: innerHTML from variable with csp_present=false → +2.0 code quality (FIX B).
- stale_18mo store 18 months since update; maintenance +6.0; invariant 0c caps publisher discount at -1.0.
Permissions Breakdown
- declarativeNetRequest medium Allows blocking/modifying network requests; core adblocker function.
- declarativeNetRequestWithHostAccess high HIGH-tier: network request interception across all HTTPS sites.
- storage low Local config/filter storage; low risk.
- scripting medium Can inject JS into pages; medium risk, justified for adblocking.
- tabs medium Tab URL access; needed for per-site ad blocking rules.
- https://*/* high Broad host access across all HTTPS sites; expected for adblocker.
Pillar Scores
Permissions3.50
Reputation4.50
Network3.50
Webstore6.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 14:18
Listing SHA
51b28cd605f1…
Force block
— not fired
Score recovered
no
Elapsed
—