Adblock Unlimited - Adblocker
jiaopkfkampgnnkckajcbdgannoipcne
Risk Score
4.21
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- 7 affiliate-network hosts hardcoded in JS (ValueCommerce, Rakuten, DMM, A8.net, Amazon affiliate) — adblocker injecting affiliate links is category fraud.
- Privacy policy is Google's generic account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — worst-case privacy disclosure.
- Developer is anonymous gmail account with no business identity, no developer name, and no dev domain.
- webRequest + scripting + <all_urls> on an extension that contacts affiliate networks creates high exfiltration and redirect risk.
- Free-webmail developer with verified publisher badge but affiliate monetization hits trigger invariant 0c/3.5-E cap on discount.
Evidence
- affiliate_hits crx 7 affiliate-network hosts in js_external_hosts: ValueCommerce, Rakuten, DMM, A8.net, Amazon affiliate, bit.ly — affiliate injection in adblocker.
- privacy_policy_generic store Policy URL is Google account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true — D clause → +10.0.
- developer_identity store developer_name empty, developer_email=hecafinbinh@gmail.com, brand_mention.developer_domain=gmail.com — no verifiable business identity.
- verified_publisher_with_monetization store verified_publisher=true but monetization_hits non-empty → invariant 0c/3.5-E caps publisher discount at -1.0.
- script_src_dynamic crx 20 files with dynamic script creation in rulesets/scripting/scriptlet/ — typical scriptlet pattern but present in non-remote-URL form.
- obfuscation_identifier crx annoyances-overlays.abort-on-property-read.js contains _0xfff1-style identifiers (obfuscation_score=0.01, low overall).
- high_perm_broad_host manifest webRequest + scripting + <all_urls> + content_scripts on http://*/* https://*/* — maximum reach with script injection capability.
- affiliate_category_mismatch crx Adblock category extension referencing Amazon/Rakuten/DMM affiliate APIs is monetization shell pattern despite stated blocking function.
Permissions Breakdown
- tabs medium Access to tab URLs and metadata; moderate risk for an adblocker.
- declarativeNetRequest medium Core adblocker permission; justified for stated function.
- storage low Stores filter lists and settings locally.
- webRequest high Can observe all network requests across all URLs; broad surveillance capability.
- scripting high Can inject scripts into any page; combined with <all_urls> enables full page manipulation.
- <all_urls> high Host permission covering every site the user visits; maximum reach.
Pillar Scores
Permissions5.50
Reputation6.50
Network4.50
Webstore7.50
Maintenance0.00
Privacy10.00
Code Quality3.00
CVE Exposure0.00
Scoring History
| v3.6 | 4.21 | Medium | block | 2026-06-16 |
| v3.4-rev | 5.18 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:46
Listing SHA
92c1cbe7a166…
Force block
— not fired
Score recovered
no
Elapsed
30.7s