AdGuard AdBlocker
Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 1 months ago
- Version
- v5.5.2.3
- Artifact
- SHA256 008…E8F
- Source
- Findings (non-IoC)
No Findings
All security checks passed
Publisher Evidence
Limited evidenceAdguard Software Ltd
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
No Threats Detected
This extension passed all security checks
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
The extension’s JavaScript makes a series of fetch requests, as shown in files such as pages/background.js:65882, pages/filtering-log.js:37660, and shared/editor.js:4279. These calls are typical for ad‑blockers that download filter lists or update rules. No network finding references an unknown or black‑listed domain; the bundle does not contain any malware signatures, credential‑related code, or attempts to modify browser settings beyond normal ad‑blocking behavior. The manifest analysis (two low‑severity entries not detailed here) did not flag any permission abuse, and there are zero indicators of code obfuscation, secret extraction, or suspicious dependencies. While the developer field is empty, the extension has over 1.7 million users, which reduces the likelihood of a malicious payload being distributed at this scale without detection.
A skeptic might argue that the numerous fetch calls could be used to exfiltrate browsing data to an undisclosed server. However, without any concrete domain evidence in the findings, and given that ad‑blockers universally require remote list updates, the presence of these fetch calls alone does not constitute malicious intent. The absence of any identified IoCs or obfuscated payloads makes the malicious hypothesis unsupported.
Key Reasons
- Only network fetch calls detected, typical for filter list updates
- No malware signatures or credential‑theft code present
- No suspicious domains or IoCs identified
- Manifest analysis shows no abnormal permission requests
- High user count suggests widespread distribution without reports
False Positive Considerations
- Network fetch findings are normal for ad‑blocking extensions
- Absence of IoC or malicious domain indicators
Reviewed 2026-05-25; recommended action: no action; model confidence 88%.
Firefox version history
Risk trend by version
3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
AdGuard VPN — Privacy & Security
Adguard Software Ltd
AdGuard AdBlocker (Beta)
Adguard Software Ltd
VaultysHub extension
Vaultys
Kindredly - A safer, private web for families
Kindredly.ai
Malwarebytes Browser Guard
Malwarebytes
VHS - Dev Tools
Vihat Software