Adblock Web - Adblocker for Chrome
jhkhlgaomejplkanglolfpcmfknnomle
Risk Score
6.44
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- 11 medium-severity CVEs across 3 outdated jQuery versions (1.7.1, 1.11.0, 3.1.1) with no CSP — XSS amplifier applies, CVE pillar capped at 10.0.
- Uninstall and install URL hijack both present — classic monetization/tracking shell pattern.
- Free Gmail dev email ('phuongrangnao@gmail.com') for extension claiming corporate name 'uadblock Inc'; no verified publisher.
- No content_security_policy (MV2+no CSP): +2.0 network penalty; script_src_dynamic findings in multiple files compound risk.
- Privacy policy hosted on Google Sites (free hosting), no retention disclosure, third_party_silence=true.
Evidence
- uninstall_url_hijack + install_url_hijack crx Both onInstalled and uninstall URL hijacks detected — webstore +3.0 each per rubric.
- free_webmail_dev store Developer email phuongrangnao@gmail.com is free webmail; claimed name 'uadblock Inc' unverifiable.
- no_csp_mv2 manifest content_security_policy is null on MV2 extension — +2.0 network penalty applied.
- cve_jquery_multiple crx 11 moderate CVEs across jquery 1.7.1, 1.11.0, 3.1.1; all below fixed_in versions; ×1.5 amplifier (no CSP + DOM lib).
- script_src_dynamic crx Dynamic script element creation in 3 JS files — remote code loading risk even if in jQuery internals.
- privacy_policy_free_hosting_no_retention api Policy on sites.google.com; scope_extension=true, data_collection=true, retention=false, third_party_silence=true.
- broad_host_webrequest_blocking manifest http://*/* + https://*/* + webRequestBlocking: can intercept and modify all browser traffic.
- identifier_obfuscation crx _0xABCD-style identifiers in domain/js/globalconstent.js — obfuscator output outside bundled libraries.
CVE Exposures (11)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@1.11.0 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.11.0 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.11.0 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
| CVE-2012-6708 | jquery@1.7.1 | moderate | 1.9.0 | Cross-Site Scripting in jquery |
| CVE-2019-11358 | jquery@1.7.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.7.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-7656 | jquery@1.7.1 | moderate | 1.9.0 | Cross-Site Scripting in jquery |
| CVE-2015-9251 | jquery@1.7.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
| CVE-2019-11358 | jquery@3.1.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.1.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.1.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- tabs medium Can enumerate open tabs and their URLs.
- http://*/* high Broad host access to all HTTP sites; content injection possible.
- https://*/* high Broad host access to all HTTPS sites; content injection possible.
- contextMenus low Adds items to right-click menu; low standalone risk.
- webRequest high Can observe all network requests across all sites.
- webRequestBlocking high Can intercept and modify/block requests across all sites.
- webNavigation medium Tracks navigation events across all pages.
- storage low Local extension storage; standard for settings.
- unlimitedStorage low No size cap on local storage; minor risk.
- notifications low Can display desktop notifications.
Pillar Scores
Permissions6.50
Reputation6.50
Network6.00
Webstore7.00
Maintenance3.50
Privacy2.00
Code Quality7.00
CVE Exposure10.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 07:47
Listing SHA
1736d90fe0cc…
Force block
— not fired
Score recovered
no
Elapsed
—