Ghostery AdBlocker for Privacy
mlomiejdfkolichcflejclcbmpeaniij
Risk Score
2.28
Risk Level:
Low
Recommendation:
✅ ALLOW
Top Risks
- Broad host_permissions (http/https/ws/wss *) combined with cookies and webRequest — justified for Adblock but high capability surface.
- innerHTML sinks in bundled npm libs (hybrids, linkedom, plotly, svg.js) with CSP present but lib-internal XSS risk remains.
- eval() in @whotracksme/reporting and new Function() in js-yaml — dynamic code execution in bundled dependencies.
- Privacy policy discloses data collection and third-party sharing; retention documented but sharing scope warrants review.
- No developer name listed in store; mitigated by verified publisher badge and ghostery.com domain.
Evidence
- verified_publisher store Ghostery is a verified publisher on Chrome Web Store; ghostery.com resolves, not throwaway.
- featured_by_google store Extension carries Google Featured badge, reducing reputation risk.
- broad_host_permissions manifest http/https/ws/wss *://*/* — full site access justified for Adblock category; -1.5 discount applied.
- code_findings_eval crx eval() in @whotracksme/reporting and new Function() in js-yaml raise dynamic-exec risk in bundled deps.
- innerHTML_sinks crx 5x dom_sink_innerhtml_userctrl in hybrids, linkedom, plotly, svg.js; CSP present mitigates extension-page XSS.
- privacy_policy api Scoped policy with collection, retention, third_party_sharing=true disclosed; adequate but sharing warrants scrutiny.
- no_bad_hosts_no_affiliates api threat_intel shows zero bad_host_hits, affiliate_hits, and monetization_hits.
- maintenance_current store Updated June 15 2026; 0 months since update — maintenance score 0.
Permissions Breakdown
- alarms low Schedules background tasks; minimal abuse potential.
- contextMenus low Adds right-click menu items; low risk.
- cookies high Can read/write cookies across sites; justified for cookie-blocking adblocker.
- declarativeNetRequest medium Core adblock mechanism; expected for category.
- declarativeNetRequestFeedback medium Reads matched rule info; expected for adblock diagnostics.
- webNavigation medium Monitors navigation events; standard for adblockers.
- storage low Local config/settings storage.
- scripting medium Injects scripts; justified for cosmetic filtering.
- tabs medium Reads tab URLs/titles; standard for adblockers.
- activeTab low Scoped to user-activated tab only.
- webRequest high Observes all requests; core adblock need, justified by category.
- offscreen low MV3 offscreen document; low risk.
- http://*/* high Broad host access; justified-broad discount applies for Adblock category.
- https://*/* high Broad host access; justified-broad discount applies for Adblock category.
- ws://*/* high WebSocket interception; expected for comprehensive adblocking.
- wss://*/* high Secure WebSocket interception; expected for comprehensive adblocking.
Pillar Scores
Permissions3.50
Reputation2.00
Network0.50
Webstore2.00
Maintenance0.00
Privacy1.00
Code Quality3.00
CVE Exposure0.00
Scoring History
| <fsssiedxf$"sssiedx | 2.64 | Low | allow | 2026-08-10 |
| %22fsssiedxf xx psssiedx | 2.17 | Low | allow | 2026-08-10 |
| %27fsssiedxffdsaxax><!--></ScRiPt>asddsssiedx | 2.27 | Low | allow | 2026-08-10 |
| 'fsssiedxf$"sssiedx | 2.77 | Low | allow | 2026-08-10 |
| "fsssiedxf$'sssiedx | 3.41 | Low | review | 2026-08-10 |
| fsssiedxf$"sssiedx | 2.22 | Low | allow | 2026-08-10 |
| <fsssiedxg$"sssiedx | 2.62 | Low | allow | 2026-08-10 |
| <fsssiedxifdsaxax><!--></ScRiPt>asddsssiedx | 2.18 | Low | allow | 2026-07-29 |
| fsssiedx<sssiedx | 2.44 | Low | allow | 2026-07-29 |
| fsssiedxh sssiedx | 2.64 | Low | allow | 2026-07-29 |
| sssieddrubricxsx | 2.61 | Low | allow | 2026-07-29 |
| fsssiedxa'sssiedx | 2.29 | Low | allow | 2026-07-28 |
| v3.6 | 2.28 | Low | allow | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:56
Listing SHA
059ae0d2abf4…
Force block
— not fired
Score recovered
no
Elapsed
32.4s