Chrome Web Store Verified

uBlock Origin Lite

by [email protected] · 21.0M users · 4.5 rating
13b4e426-c221-53cd-bd9b-ef3db7a3d580 | v2026.926.2202
59/ 100
MEDIUM risk
No change since v2026.920.1710
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (59/100) still counts them.

Analysis record

Analysed
2 days ago
Version
v2026.926.2202
Artifact
SHA256 E27…1E6
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

8 detail rows

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

67
Noisy-finding weight
x1.00
Publisher domain
raymondhill.net
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
8
Portfolio

12 evidence rows available.

Finding Categories

8
Obfuscation

Requested Permissions

9 permissions
<all_urls>

Access and modify data on every website you visit

Dangerous
activeTab
Medium
alarms
Low
declarativeNetRequest
Low
offscreen
Low
scripting
Low
storage
Low
unlimitedStorage
Low
userScripts
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

uBlock Origin Lite is a content blocker developed by Raymond Hill, the same developer behind the original uBlock Origin. The extension's package contains filter rule sets organized by language and region, such as rulesets/scripting/scriptlet/main/easyprivacy.js, rulesets/scripting/scriptlet/main/chn-0.js, and rulesets/scripting/scriptlet/main/fra-0.js. These files implement the blocking logic that prevents ads, trackers, and other unwanted content from loading in the browser.

The 60 network findings all originate from these scriptlet files. Each finding title follows the pattern NET-XMLHTTPREQUEST-rulesets/scripting/scriptlet/main/... or NET-FETCH-rulesets/scripting/scriptlet/main/.... These are not outbound connections to suspicious servers. Scriptlets in content blockers use XMLHttpRequest and fetch calls to intercept and neutralize network requests made by web pages. A scriptlet in easyprivacy.js at line 992 blocking a tracking request will trigger a network finding because the scanner sees a fetch call in the source code. This is the mechanism by which the extension does its job.

The 8 obfuscation findings break down into two groups. Seven are OBFUSCATION-INVISIBLE_ZERO_WIDTH matches in locale files like _locales/te/messages.json (Telugu), _locales/si/messages.json (Sinhala), _locales/ml/messages.json (Malayalam), and _locales/fa/messages.json (Farsi). These writing systems use zero-width joiner and zero-width non-joiner characters as legitimate parts of their orthography. The scanner flags them because it cannot distinguish between steganographic use and normal text composition. The same rule fires on rulesets/scripting/specific/irn-0.json and rulesets/scripting/specific/deu-0.json, which contain filter rules with characters from Persian and German respectively. The eighth obfuscation finding, OBFUSCATION-FROMCHARCODE_BULK at rulesets/scripting/scriptlet/main/spa-1.js:3001, matches a String.fromCharCode call used to construct DOM manipulation strings dynamically. This is standard practice in ad blocker scriptlets, which build CSS selectors and HTML snippets at runtime.

No malware signatures matched. No indicators of compromise pointed to external command-and-control infrastructure. No credential access patterns appeared. The extension declares no host permissions and no special permissions beyond what Manifest V3 requires for content blocking.

A skeptic might point to the 7 high-severity obfuscation findings and argue that invisible characters hidden across multiple files indicate deliberate code concealment. But the files in question are locale translations and regional filter lists. Telugu, Sinhala, Malayalam, and Farsi scripts require zero-width characters for correct rendering. The scanner's zero-width detector does not account for writing system requirements, which is why it fires on every localized extension that supports South Asian or Middle Eastern languages. The fromCharCode match in the Spanish scriptlet file is equally mundane. Ad blocker scriptlets construct blocking rules as strings, and String.fromCharCode is one of several ways to assemble those strings. None of these findings represent hidden payloads or covert channels.

With 21 million users and a developer identity tied to one of the most scrutinized open-source projects in the browser extension ecosystem, uBlock Origin Lite operates exactly as expected. Every finding in this scan traces back to the mechanics of content blocking or the requirements of multilingual text.

Key Reasons

  • Extension is uBlock Origin Lite by Raymond Hill, a verified open-source developer with 21 million users
  • All 60 network findings are XMLHttpRequest and fetch calls inside content blocking scriptlet files
  • Zero-width obfuscation findings are legitimate characters in South Asian and Middle Eastern locale files
  • No malware signatures, no indicators of compromise, and no credential access patterns detected
  • Extension declares no special permissions consistent with a Manifest V3 content blocker

False Positive Considerations

  • Zero-width characters in locale files for Telugu, Sinhala, Malayalam, and Farsi scripts are legitimate orthographic characters
  • NET-XMLHTTPREQUEST and NET-FETCH findings in scriptlet files are the mechanism by which content blockers intercept page requests
  • String.fromCharCode in scriptlet files is used for dynamic DOM rule construction, not payload encoding

Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 95%.

Chrome version history

Risk trend by version

4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
59
Change since first
-9
Change from previous
No change
Versions:
First analyzed version
2026.901.1442
Sep 7, 2026
Risk range
59 to 68
Across analyzed versions
Latest analyzed version
2026.926.2202
Sep 29, 2026
Selected version
medium
Version
v2026.926.2202
2 days ago
Risk score
59
Findings
68
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

uBO Lite (uBOL) is an efficient MV3-based content blocker. The default ruleset corresponds to uBlock Origin's default filterset: - uBlock Origin's built-in filter lists - EasyList - EasyPrivacy - Peter Lowe’s Ad and tracking server list You can enable more rulesets by visiting the options page -- click the _Cogs_ icon in the popup panel. uBOL is entirely declarative, meaning there is no need for a permanent uBOL process for the filtering to occur, and CSS/JS injection-based content filtering is performed reliably by the browser itself rather than by the extension. This means that uBOL itself does not consume CPU/memory resources while content blocking is ongoing -- uBOL's service worker process is required _only_ when you interact with the popup panel or the option pages.

Frequently Asked Questions