Is "Block Site" on Firefox Add-ons Safe to Install?

Ray · firefox · v0.5.7

This extension will block access to websites of your choosing. A master password controls all customization options, as well as access to any blocked site. It’s also possible to redirect navigation from one specific website to another. Preview: https://www.youtube.com/watch?v=maE-gOUSH4c Features: 1. Block unwanted domains. 2. Prevent access to a range of websites using wildcard matching or regular expression matching. 3. Reverse mode allows access to only some hostnames and blocks access to all others. 4. Custom redirection; you can redirect a single blocked hostname to a new destination. 5. Display a custom message on blocked pages. 6. Time and date based blocking. Only block access to the websites at specified times and dates. This feature can be configured per hostname. 7. Protect data leakage. This extension prevents certain hostnames from gathering network activity from your computer, since blocking occurs before any network request is emitted to the server. 8. Auto-closes blocked tabs after a period of time. 10. Closes annoying pop-ups as soon as the opening request is received. 11. Pause and resume blocking from the right-click context menu of the toolbar button. 12. Supports overwriting configurations by managed storage For the FAQs and general feature suggestions please use: https://webextension.org/listing/block-site.html For technical bug reports use: https://github.com/ray-lothian/Block-Site/issues

Risk Assessment

Analyzed
49.76
out of 100
MEDIUM

184 security findings detected across all analyzers

Firefox extension requesting 8 permissions

Severity Breakdown

0
Critical
67
High
117
Medium
0
Low
0
Info

Finding Categories

67
Malware Signatures
1
Network
116
IoC Indicators

YARA Rules Matched

10 rules(67 hits)
postinstall file manipulation postinstall network communication postinstall persistence mechanism NoUseWeakRandom postinstall system command postinstall file download postinstall obfuscation postinstall crypto operations LocalStorageShouldNotBeUsed AlertStatementsShouldNotBeUsed

Requested Permissions

8 permissions
<all_urls>

Access and modify data on every website you visit

Dangerous
activeTab
Medium
storage
Low
notifications
Low
alarms
Low
contextMenus
Low
declarativeNetRequestWithHostAccess
Low
idle
Low

About This Extension

This extension will block access to websites of your choosing. A master password controls all customization options, as well as access to any blocked site. It’s also possible to redirect navigation from one specific website to another. Preview: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/d44b98f396878c6af46b22451c6fcbecf0934634c20e1be4b642df1b3d4984a6/https%3A//www.youtube.com/watch%3Fv=maE-gOUSH4c" rel="nofollow">https://www.youtube.com/watch?v=maE-gOUSH4c</a> Features: 1. Block unwanted domains. 2. Prevent access to a range of websites using wildcard matching or regular expression matching. 3. Reverse mode allows access to only some hostnames and blocks access to all others. 4. Custom redirection; you can redirect a single blocked hostname to a new destination. 5. Display a custom message on blocked pages. 6. Time and date based blocking. Only block access to the websites at specified times and dates. This feature can be configured per hostname. 7. Protect data leakage. This extension prevents certain hostnames from gathering network activity from your computer, since blocking occurs before any network request is emitted to the server. 8. Auto-closes blocked tabs after a period of time. 10. Closes annoying pop-ups as soon as the opening request is received. 11. Pause and resume blocking from the right-click context menu of the toolbar button. 12. Supports overwriting configurations by managed storage For the FAQs and general feature suggestions please use: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/7a2f16d729952b1cbe776326042c0b9d7956dca0db852ecb74512c58af884b91/https%3A//webextension.org/listing/block-site.html" rel="nofollow">https://webextension.org/listing/block-site.html</a> For technical bug reports use: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/1da51d433ab23e9619a9c0473b31a0f5ede4222ce839c33414488d25735474f2/https%3A//github.com/ray-lothian/Block-Site/issues" rel="nofollow">https://github.com/ray-lothian/Block-Site/issues</a>

Detailed Findings

68 total

YARA Rule Matches

10 rules

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

URLs
37
IP Addresses
6
Domains
75
Strings
116

All Indicators · 116

IP
detected IP: e::af

XIOC detected IP: e::af

extracted_from_files

URL
detected URL: https://addons.mozilla.org/firefox/addon/block-website/reviews/';

XIOC detected URL: https://addons.mozilla.org/firefox/addon/block-website/reviews/';

extracted_from_files

Domain
detected Domain: request.date

XIOC detected Domain: request.date

extracted_from_files

Domain
detected Domain: request.host

XIOC detected Domain: request.host

extracted_from_files

URL
detected URL: http://mozilla.org/MPL/2.0/.

XIOC detected URL: http://mozilla.org/MPL/2.0/.

extracted_from_files

URL
detected URL: http://addons.mozilla.org/ca/crl.pem0N

XIOC detected URL: http://addons.mozilla.org/ca/crl.pem0N

extracted_from_files

URL
detected URL: https://github.com/ray-lothian/tld.js/releases/tag/0.1.0

XIOC detected URL: https://github.com/ray-lothian/tld.js/releases/tag/0.1.0

extracted_from_files

URL
detected URL: http://www.w3.org/2000/svg

XIOC detected URL: http://www.w3.org/2000/svg

extracted_from_files

URL
detected URL: https://github.com/ray-lothian/Block-Site/issues/6

XIOC detected URL: https://github.com/ray-lothian/Block-Site/issues/6

extracted_from_files

Domain
detected Domain: w.id

XIOC detected Domain: w.id

extracted_from_files

Domain
detected Domain: o.name

XIOC detected Domain: o.name

extracted_from_files

Domain
detected Domain: a.name

XIOC detected Domain: a.name

extracted_from_files

Domain
detected Domain: rules.map

XIOC detected Domain: rules.map

extracted_from_files

Domain
detected Domain: hasharray.map

XIOC detected Domain: hasharray.map

extracted_from_files

Domain
detected Domain: request.hosts.map

XIOC detected Domain: request.hosts.map

extracted_from_files

Domain
detected Domain: sender.tab.id

XIOC detected Domain: sender.tab.id

extracted_from_files

Domain
detected Domain: sp.map

XIOC detected Domain: sp.map

extracted_from_files

Domain
detected Domain: input.click

XIOC detected Domain: input.click

extracted_from_files

Domain
detected Domain: e.target.dataset.id

XIOC detected Domain: e.target.dataset.id

extracted_from_files

Domain
detected Domain: start.dataset.id

XIOC detected Domain: start.dataset.id

extracted_from_files

Domain
detected Domain: e.target

XIOC detected Domain: e.target

extracted_from_files

Domain
detected Domain: console.info

XIOC detected Domain: console.info

extracted_from_files

Domain
detected Domain: win.top

XIOC detected Domain: win.top

extracted_from_files

Domain
detected Domain: ns.adobe.com

XIOC detected Domain: ns.adobe.com

extracted_from_files

Domain
detected Domain: www.gimp.org

XIOC detected Domain: www.gimp.org

extracted_from_files

URL
detected Domain: purl.org

XIOC detected Domain: purl.org

extracted_from_files

Domain
detected Domain: e.dataset.id

XIOC detected Domain: e.dataset.id

extracted_from_files

Domain
detected Domain: add0n.com

XIOC detected Domain: add0n.com

extracted_from_files

Domain
detected Domain: www.bing.com

XIOC detected Domain: www.bing.com

extracted_from_files

Domain
detected Domain: www.youtube.com

XIOC detected Domain: www.youtube.com

extracted_from_files

Domain
detected Domain: evil.co.uk

XIOC detected Domain: evil.co.uk

extracted_from_files

Domain
detected Domain: co.uk

XIOC detected Domain: co.uk

extracted_from_files

Domain
detected Domain: example.org

XIOC detected Domain: example.org

extracted_from_files

Domain
detected Domain: rule.parts

XIOC detected Domain: rule.parts

extracted_from_files

Domain
detected Domain: www.mozilla.org

XIOC detected Domain: www.mozilla.org

extracted_from_files

Domain
detected Domain: webextension.org

XIOC detected Domain: webextension.org

extracted_from_files

Domain
detected Domain: div.info

XIOC detected Domain: div.info

extracted_from_files

Domain
detected Domain: relative.search

XIOC detected Domain: relative.search

extracted_from_files

Domain
detected Domain: result.host

XIOC detected Domain: result.host

extracted_from_files

Domain
detected Domain: not.evil.com

XIOC detected Domain: not.evil.com

extracted_from_files

Domain
detected Domain: vil.com

XIOC detected Domain: vil.com

extracted_from_files

Domain
detected Domain: evil.com

XIOC detected Domain: evil.com

extracted_from_files

URL
detected URL: https://www.youtube.com/watch?v=maE-gOUSH4c'

XIOC detected URL: https://www.youtube.com/watch?v=maE-gOUSH4c'

extracted_from_files

URL
detected URL: https://mathiasbynens.be/notes/javascript-encoding

XIOC detected URL: https://mathiasbynens.be/notes/javascript-encoding

extracted_from_files

URL
detected URL: https://webextension.org/listing/block-site.html

XIOC detected URL: https://webextension.org/listing/block-site.html

extracted_from_files

Domain
detected Domain: xs.map

XIOC detected Domain: xs.map

extracted_from_files

Domain
detected Domain: this.host

XIOC detected Domain: this.host

extracted_from_files

Domain
detected Domain: this.search

XIOC detected Domain: this.search

extracted_from_files

URL
detected Domain: url.prototype.format.call

XIOC detected Domain: url.prototype.format.call

extracted_from_files

Domain
detected Domain: relative.host

XIOC detected Domain: relative.host

extracted_from_files

Domain
detected Domain: result.search

XIOC detected Domain: result.search

extracted_from_files

Domain
detected Domain: mathiasbynens.be

XIOC detected Domain: mathiasbynens.be

extracted_from_files

Domain
detected Domain: tools.ietf.org

XIOC detected Domain: tools.ietf.org

extracted_from_files

Domain
detected Domain: code.google.com

XIOC detected Domain: code.google.com

extracted_from_files

Domain
detected Domain: foo.com

XIOC detected Domain: foo.com

extracted_from_files

Domain
detected Domain: www.example.com

XIOC detected Domain: www.example.com

extracted_from_files

Domain
detected Domain: freeglobal.global

XIOC detected Domain: freeglobal.global

extracted_from_files

Domain
detected Domain: object.prototype.hasownproperty.call

XIOC detected Domain: object.prototype.hasownproperty.call

extracted_from_files

Domain
detected Domain: o.host

XIOC detected Domain: o.host

extracted_from_files

Domain
detected Domain: o.search

XIOC detected Domain: o.search

extracted_from_files

Domain
detected Domain: window.top

XIOC detected Domain: window.top

extracted_from_files

Domain
detected Domain: chrome.google.com

XIOC detected Domain: chrome.google.com

extracted_from_files

Domain
detected Domain: microsoftedge.microsoft.com

XIOC detected Domain: microsoftedge.microsoft.com

extracted_from_files

Domain
detected Domain: addons.opera.com

XIOC detected Domain: addons.opera.com

extracted_from_files

Domain
detected Domain: mths.be

XIOC detected Domain: mths.be

extracted_from_files

Domain
detected Domain: ps.map

XIOC detected Domain: ps.map

extracted_from_files

Domain
detected Domain: read.plural.select

XIOC detected Domain: read.plural.select

extracted_from_files

Domain
detected Domain: date.now

XIOC detected Domain: date.now

extracted_from_files

Domain
detected Domain: alarm.name

XIOC detected Domain: alarm.name

extracted_from_files

Domain
detected Domain: github.com

XIOC detected Domain: github.com

extracted_from_files

Domain
detected Domain: www.w3.org

XIOC detected Domain: www.w3.org

extracted_from_files

Domain
detected Domain: location.search

XIOC detected Domain: location.search

extracted_from_files

Domain
detected Domain: addons.mozilla.org

XIOC detected Domain: addons.mozilla.org

extracted_from_files

Domain
detected Domain: content-signature.mozilla.org

XIOC detected Domain: content-signature.mozilla.org

extracted_from_files

Domain
detected Domain: t1a2a1293dae964c664e4f1d54a8ce28b.4d3fe5ea73bd6ff692fcc9d91f19f218.addons.mozilla.org

XIOC detected Domain: t1a2a1293dae964c664e4f1d54a8ce28b.4d3fe5ea73bd6ff692fcc9d91f19f218.addons.mozilla.org

extracted_from_files

Domain
detected Domain: www.google.com

XIOC detected Domain: www.google.com

extracted_from_files

Domain
detected Domain: r.id

XIOC detected Domain: r.id

extracted_from_files

Domain
detected Domain: prefs.map

XIOC detected Domain: prefs.map

extracted_from_files

Domain
detected Domain: tab.id

XIOC detected Domain: tab.id

extracted_from_files

IP
detected IP: ::bef

XIOC detected IP: ::bef

extracted_from_files

IP
detected IP: ::

XIOC detected IP: ::

extracted_from_files

IP
detected IP: 9::

XIOC detected IP: 9::

extracted_from_files

IP
detected IP: 0::

XIOC detected IP: 0::

extracted_from_files

Domain
detected Domain: mozilla.org

XIOC detected Domain: mozilla.org

extracted_from_files

Domain
detected Domain: signingca1.addons.mozilla.org

XIOC detected Domain: signingca1.addons.mozilla.org

extracted_from_files

Domain
detected Domain: mozilla.com

XIOC detected Domain: mozilla.com

extracted_from_files

URL
detected URL: https://mths.be/punycode

XIOC detected URL: https://mths.be/punycode

extracted_from_files

URL
detected URL: https://addons.opera.com/extensions/details/block-site-2/';

XIOC detected URL: https://addons.opera.com/extensions/details/block-site-2/';

extracted_from_files

URL
detected URL: https://tools.ietf.org/html/rfc3492#section-3.4

XIOC detected URL: https://tools.ietf.org/html/rfc3492#section-3.4

extracted_from_files

URL
detected URL: https://microsoftedge.microsoft.com/addons/detail/deiilejafkhhgekckholkdhfhopcnmeb';

XIOC detected URL: https://microsoftedge.microsoft.com/addons/detail/deiilejafkhhgekckholkdhfhopcnmeb';

extracted_from_files

URL
detected URL: https://chrome.google.com/webstore/detail/block-site/lebiggkccaodkkmjeimmbogdedcpnmfb/reviews/';

XIOC detected URL: https://chrome.google.com/webstore/detail/block-site/lebiggkccaodkkmjeimmbogdedcpnmfb/reviews/';

extracted_from_files

URL
detected URL: https://www.mozilla.org/en-US/MPL/

XIOC detected URL: https://www.mozilla.org/en-US/MPL/

extracted_from_files

URL
detected URL: https://github.com/lunu-bounir/notification-view

XIOC detected URL: https://github.com/lunu-bounir/notification-view

extracted_from_files

URL
detected URL: https://github.com/oncletom/tld.js/issues/95

XIOC detected URL: https://github.com/oncletom/tld.js/issues/95

extracted_from_files

URL
detected URL: http://www.example.com

XIOC detected URL: http://www.example.com

extracted_from_files

URL
detected URL: http://foo.com

XIOC detected URL: http://foo.com

extracted_from_files

URL
detected URL: https://code.google.com/p/chromium/issues/detail?id=25916

XIOC detected URL: https://code.google.com/p/chromium/issues/detail?id=25916

extracted_from_files

URL
detected URL: https://github.com/joyent/node/issues/1707

XIOC detected URL: https://github.com/joyent/node/issues/1707

extracted_from_files

URL
detected URL: http://ns.adobe.com/xap/1.0/

XIOC detected URL: http://ns.adobe.com/xap/1.0/

extracted_from_files

URL
detected URL: http://purl.org/dc/elements/1.1/

XIOC detected URL: http://purl.org/dc/elements/1.1/

extracted_from_files

URL
detected URL: http://www.gimp.org/xmp/

XIOC detected URL: http://www.gimp.org/xmp/

extracted_from_files

URL
detected URL: http://ns.adobe.com/exif/1.0/

XIOC detected URL: http://ns.adobe.com/exif/1.0/

extracted_from_files

URL
detected URL: http://ns.adobe.com/tiff/1.0/

XIOC detected URL: http://ns.adobe.com/tiff/1.0/

extracted_from_files

URL
detected URL: http://www.w3.org/1999/02/22-rdf-syntax-ns#

XIOC detected URL: http://www.w3.org/1999/02/22-rdf-syntax-ns#

extracted_from_files

URL
detected URL: https://webextension.org/custom-component/notification-view/index.html

XIOC detected URL: https://webextension.org/custom-component/notification-view/index.html

extracted_from_files

URL
detected URL: https://github.com/ray-lothian/Block-Site/issues/51

XIOC detected URL: https://github.com/ray-lothian/Block-Site/issues/51

extracted_from_files

URL
detected URL: https://add0n.com/block-site.html#faq15

XIOC detected URL: https://add0n.com/block-site.html#faq15

extracted_from_files

URL
detected URL: https://www.bing.com

XIOC detected URL: https://www.bing.com

extracted_from_files

URL
detected URL: https://github.com/ray-lothian/Block-Site/issues/111

XIOC detected URL: https://github.com/ray-lothian/Block-Site/issues/111

extracted_from_files

URL
detected URL: https://github.com/ray-lothian/Block-Site/issues/85

XIOC detected URL: https://github.com/ray-lothian/Block-Site/issues/85

extracted_from_files

URL
detected URL: http://ns.adobe.com/xap/1.0/sType/ResourceEvent#

XIOC detected URL: http://ns.adobe.com/xap/1.0/sType/ResourceEvent#

extracted_from_files

URL
detected URL: http://ns.adobe.com/xap/1.0/mm/

XIOC detected URL: http://ns.adobe.com/xap/1.0/mm/

extracted_from_files

Hash
detected MD5 Hash: 4d3fe5ea73bd6ff692fcc9d91f19f218

XIOC detected MD5 Hash: 4d3fe5ea73bd6ff692fcc9d91f19f218

extracted_from_files

Domain
detected Domain: object.prototype.tostring.call

XIOC detected Domain: object.prototype.tostring.call

extracted_from_files

Domain
detected Domain: not.evil.co.uk

XIOC detected Domain: not.evil.co.uk

extracted_from_files

Domain
detected Domain: example.co.uk

XIOC detected Domain: example.co.uk

extracted_from_files

Security Analysis Summary

Security Analysis Overview

Block Site is a Firefox Add-ons extension published by Ray. Version 0.5.7 has been analyzed by the Risky Plugins security platform, receiving a risk score of 49.76/100 (MEDIUM risk) based on 184 security findings.

Risk Assessment

This extension presents moderate security risk. Several findings were detected that may warrant attention. Users should carefully review the permissions and findings before installation.

Findings Breakdown

  • High: 67 finding(s)
  • Medium: 117 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

Block Site is published by Ray on the Firefox Add-ons marketplace. The extension has approximately 73K users.

Recommendation

Exercise caution with this extension. Review the detailed findings and ensure the requested permissions align with the extension's stated functionality before installation.

Frequently Asked Questions