AdBlock - Ads and Youtube
nonajfcfdpeheinkafjiefpdhfalffof
Risk Score
6.18
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Gmail developer + YouTube brand impersonation: unverified individual claiming YouTube adblock with no organizational accountability.
- Privacy policy admits data collection and third-party sharing but is NOT scoped to this extension — maximum privacy risk score.
- Uninstall URL hijack configured — extension redirects user on removal, a known monetization/tracking abuse pattern.
- scripting + broad host_permissions (<all_urls>) allows arbitrary JS injection into every site the user visits.
- Small install count (447) with HIGH-tier permissions signals potential tail-attack-surface / sleeper extension.
Evidence
- brand_impersonation store YouTube brand mentioned in title/description; developer is unverified gmail user, not YouTube/Google.
- uninstall_url_hijack crx uninstall_url_hijack=true — extension sets chrome.runtime.setUninstallURL to a 3rd-party destination.
- privacy_policy_generic_admits_sharing api Policy fetched: scope_extension=false, data_collection=true, third_party_sharing=true → v3.5 rule D: +10.0.
- free_webmail_developer store Developer email carrollmarvin74@gmail.com; no verified business identity.
- broad_host_permissions manifest host_permissions and content_scripts both cover http://*/* and https://*/* with scripting perm.
- small_install_high_perm api install_perm_anomaly: 447 installs + HIGH-tier permissions = tail-attack-surface flag.
- js_external_host crx Extension contacts adblock-ads-and-yt.pro — same domain as privacy policy, unknown content served.
- no_csp manifest csp_present=false on MV3 extension; no additional CSP hardening beyond browser default.
Permissions Breakdown
- storage low Local data persistence; standard for adblock filter lists.
- tabs medium Access to tab URLs and titles across all sites.
- declarativeNetRequest medium Core adblock capability; can intercept/block network requests.
- scripting high Combined with broad host_permissions, enables arbitrary script injection on all sites.
- http://*/* high Broad host access; covers every HTTP site the user visits.
- https://*/* high Broad host access; covers every HTTPS site including banking/auth.
Pillar Scores
Permissions6.50
Reputation8.50
Network3.50
Webstore7.50
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:09
Listing SHA
2fe6ea7c4a34…
Force block
— not fired
Score recovered
no
Elapsed
—