Video Ad Block Youtube
okepkpmjhegbhmnnondmminfgfbjddpb
Risk Score
4.61
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Gmail developer with YouTube brand impersonation and no verified publisher status.
- Uninstall URL hijack active — extension registers a 3rd-party URL on uninstall.
- Privacy policy admits data collection AND third-party sharing but is hosted on free Google Sites.
- scripting + <all_urls> allows arbitrary JS injection on every site user visits.
- js_external_hosts includes ytadskip.com — unknown third-party domain contacted at runtime.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=[youtube]; confirmed_owner=false; dev email is gmail.
- free_webmail_developer store developer_email=emredenizadem@gmail.com; no verified publisher; domain_age_ct not queried (free webmail).
- uninstall_url_hijack crx uninstall_url_hijack=true; uninstall_url_target=null (target unresolved but flag is set).
- privacy_policy_data_collection_third_party api fetched=true, scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
- external_host_unknown crx js_external_hosts includes ytadskip.com — not a recognized CDN or dev-owned domain.
- no_csp manifest content_security_policy=null; MV3 default applies but no explicit CSP declared.
- broad_host_access manifest host_permissions=[<all_urls>] paired with scripting permission and content_scripts on <all_urls>.
- privacy_policy_free_hosting api Privacy policy hosted on sites.google.com (free hosting); no retention disclosure.
Permissions Breakdown
- declarativeNetRequest medium Blocks/modifies network requests; core adblock function, medium risk.
- declarativeNetRequestFeedback low Read-only feedback on blocked requests; low standalone risk.
- scripting high Allows dynamic script injection into any page via <all_urls>.
- storage low Local extension storage only; low risk.
- <all_urls> (host_permission) high Full access to every site the user visits; broad attack surface.
- <all_urls> (content_scripts) high Content scripts injected on all URLs; wide reach.
Pillar Scores
Permissions5.50
Reputation8.00
Network2.00
Webstore5.50
Maintenance0.00
Privacy5.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:01
Listing SHA
e240dac155b7…
Force block
— not fired
Score recovered
no
Elapsed
21.8s