Firefox Add-ons Verified

AAEBlocker

by Abdullah Asım Ersin · 1 users
240e2f20-5d28-548e-bfc4-40671bd8a53e | v11.0.0
85/ 100
CRITICAL risk
No change since v1.74.0
Risk verdict
Do not install

Score-based assessment (critical risk, 85/100). No analyst review available.

Analysis record

Analysed
4 days ago
Version
v11.0.0
Artifact
SHA256 38E…329
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

1000 detail rows
Showing 25 of 41 · highest severity first

YARA Rule Matches

18 rules
SeverityRuleHitsFilesMetadata
LOWcredential env files 85
venv/lib/python3.14/site-packages/pip/_vendor/msgpack/__init__.pyvenv/lib/python3.14/site-packages/pip/_vendor/distro/distro.pyvenv/lib64/python3.14/site-packages/pip/_vendor/platformdirs/__pycache__/android.cpython-314.pyc +82 more
-
LOWRedirectToUnknownPath 4
venv/lib/python3.14/site-packages/pip/_vendor/requests/models.pyvenv/lib/python3.14/site-packages/pip/_vendor/requests/auth.pyvenv/lib64/python3.14/site-packages/pip/_vendor/requests/models.py +1 more
-
LOWWarpStrings 1
assets/ublock/badware.min.txt
-
LOWCerberus 1
assets/ublock/filters.min.txt
-
LOWWeakSSLTLSProtocolsShouldNotBeUsed 12
venv/lib64/python3.14/site-packages/pip/_vendor/urllib3/contrib/_securetransport/low_level.pyvenv/lib/python3.14/site-packages/pip/_vendor/urllib3/contrib/_securetransport/__pycache__/low_level.cpython-314.pycvenv/lib/python3.14/site-packages/pip/_vendor/urllib3/__pycache__/connection.cpython-314.pyc +9 more
-
LOWcredential skype data 4
assets/ublock/filters.min.txtassets/ublock/privacy.min.txtassets/ublock/unbreak.min.txt +1 more
-
LOWpostinstall persistence mechanism 30
venv/lib/python3.14/site-packages/pip/_internal/pyproject.pyvenv/lib/python3.14/site-packages/pip/_vendor/packaging/licenses/_spdx.pyassets/thirdparties/easylist/easyprivacy.txt +27 more
-
LOWLocalStorageShouldNotBeUsed 10
assets/ublock/quick-fixes.min.txtjs/3p-filters.jsjs/1p-filters.js +7 more
-
LOWDebuggerStatementsShouldNotBeUsed 13
js/resources/prevent-addeventlistener.jsjs/resources/scriptlets.jsjs/static-dnr-filtering.js +10 more
-
LOWScarhiknStrings 1
assets/thirdparties/urlhaus-filter/urlhaus-filter-online.txt
-
LOWpostinstall file download 472
venv/lib/python3.14/site-packages/pip/_internal/commands/__pycache__/configuration.cpython-314.pycvenv/lib64/python3.14/site-packages/pip/_vendor/rich/default_styles.pyjs/filtering-engines.js +469 more
-
LOWNoUseWeakRandom 14
js/lib/tfjs/tf.min.jsjs/aae-crowdsource.jsweb_accessible_resources/fingerprint3.js +11 more
-
LOWNoUseEval 9
venv/lib64/python3.14/site-packages/pip/_vendor/pygments/formatters/__init__.pyvenv/lib64/python3.14/site-packages/pip/_vendor/rich/markup.pyjs/lib/tfjs/tf-tflite.min.js +6 more
-
LOWpostinstall file manipulation 22
venv/lib/python3.14/site-packages/pip/_vendor/pygments/lexers/python.pyvenv/lib/python3.14/site-packages/pip/_internal/req/req_set.pyvenv/lib64/python3.14/site-packages/pip/_vendor/pygments/__pycache__/token.cpython-314.pyc +19 more
-
LOWpostinstall obfuscation 192
venv/lib/python3.14/site-packages/pip/_vendor/requests/__pycache__/sessions.cpython-314.pycvenv/lib64/python3.14/site-packages/pip/_internal/cli/main.pyvenv/lib64/python3.14/site-packages/pip/_vendor/pygments/lexer.py +189 more
-
LOWpostinstall registry modification 53
venv/lib64/python3.14/site-packages/pip/_internal/cli/base_command.pyvenv/lib/python3.14/site-packages/pip/_vendor/pkg_resources/__init__.pyassets/ublock/filters.min.txt +50 more
-
LOWAlertStatementsShouldNotBeUsed 2
js/aae-settings-ui.jsassets/ublock/filters.min.txt
-
LOWpostinstall environment access 34
venv/lib/python3.14/site-packages/pip/_internal/models/search_scope.pyvenv/lib/python3.14/site-packages/pip/_internal/models/index.pyvenv/lib64/python3.14/site-packages/pip/_internal/commands/freeze.py +31 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

159,204 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

Abdullah Asım Ersin

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

32
Noisy-finding weight
x1.00
Publisher domain
lafolsun.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

10
Obfuscation
29
Network
159,204
IoC Indicators

YARA Rules Matched

18 rules(959 hits)
credential env files RedirectToUnknownPath WarpStrings Cerberus WeakSSLTLSProtocolsShouldNotBeUsed credential skype data postinstall persistence mechanism LocalStorageShouldNotBeUsed DebuggerStatementsShouldNotBeUsed ScarhiknStrings postinstall file download NoUseWeakRandom NoUseEval postinstall file manipulation postinstall obfuscation postinstall registry modification +2 more

Requested Permissions

23 permissions
<all_urls>

Access and modify data on every website you visit

Dangerous
http://*/*
Dangerous
https://*/*
Dangerous
file://*/*
Dangerous
webRequest

Intercept, modify, and block all network requests

High
webRequestBlocking

Block network requests before they complete

High
tabs
Medium
alarms
Low
dns
Low
menus
Low
privacy
Low
storage
Low
unlimitedStorage
Low
webNavigation
Low
https://easylist.to/*
Low
https://*.fanboy.co.nz/*
Low
https://filterlists.com/*
Low
https://forums.lanik.us/*
Low
https://github.com/*
Low
https://*.github.io/*
Low
https://github.com/AAEConsole/*
Low
https://aaeconsole.team/*
Low
https://*.reddit.com/r/AAEBlocker/*
Low

Security Analysis Summary

Security Analysis Overview

AAEBlocker is a Firefox Add-ons extension published by Abdullah Asım Ersin. Version 11.0.0 has been analyzed by the Risky Plugins security platform, receiving a risk score of 85/100 (CRITICAL risk) based on 162557 security findings.

Risk Assessment

This extension presents critical security risk. Severe issues were detected, potentially including malware indicators, exposed secrets, or dangerous behaviors. Installation is strongly discouraged until these issues are addressed.

Findings Breakdown

  • High: 7 finding(s)
  • Medium: 159238 finding(s)
  • Low: 3312 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

AAEBlocker is published by Abdullah Asım Ersin on the Firefox Add-ons marketplace. The extension has approximately 1 users.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

Firefox version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
85
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
1.74.0
Sep 9, 2026
Risk range
85 to 85
Across analyzed versions
Latest analyzed version
11.0.0
Sep 16, 2026
Selected version
critical
Version
v11.0.0
4 days ago
Risk score
85
Findings
162557
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

AAEBlocker is a smart shield and defense system redesigned from the ground up for the modern web, where classic ad blockers fall short. Instead of relying on static rules, it acts like an "Artificial Intelligence", analyzing page elements to recognize ads dynamically. ⚡ KEY FEATURES: AI Engine (Skynet): Detects hidden sponsored content, Anti-Adblock warnings, and phishing attempts directly from the DOM structure using neural networks. Federated Learning Network: Newly discovered ad selectors by AAEBlocker users worldwide are collected anonymously in the cloud and securely synchronized to your device. Autonomous Idle Trainer: The extension continuously trains its neural network in the background when your browser is idle (consuming &lt;1% CPU and &lt;1MB RAM) without slowing you down. Cyber Terminal HUD: Monitor the AI's operations, memory consumption, and learning loops in real-time with a stunning Matrix-themed Cyber Terminal in the settings. Multi-language Support: Automatically switches to English or Turkish based on your browser's default language settings! Contact &amp; Community (Open Source): 🔗 Source Code (GitHub): <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/b5eb178ff1c3f830074a5e6a31f93f186eb2ddf7929dd8bffe8eff44ca2975c3/https%3A//github.com/Abdullaherain0131/AAEBlocker" rel="nofollow">https://github.com/Abdullaherain0131/AAEBlocker</a> 🐛 Report Bugs (Issues): <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/63858c815c0305f0dca1438b626f9a5229070e643dabe6290a64cd996b38535c/https%3A//github.com/Abdullaherain0131/AAEBlocker/issues" rel="nofollow">https://github.com/Abdullaherain0131/AAEBlocker/issues</a> 💬 Community &amp; Patches (Discussions): <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/93fcf3df5f86c2e865813b84f9fbec78ebf1ca900722aab1c88af06e6cfc7bca/https%3A//github.com/Abdullaherain0131/AAEBlocker/discussions" rel="nofollow">https://github.com/Abdullaherain0131/AAEBlocker/discussions</a> (Share your own patches and rules here) 📧 Support Email: <a href="/" rel="nofollow">[email protected]</a>

Frequently Asked Questions