Adblock Plus
The AI review rates the findings as likely false positive, but the risk score (60/100) still counts them.
Analysis record
- Analysed
- Today
- Version
- v4.45.0
- Artifact
- SHA256 ABA…46E
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
Limited evidenceAdblock Plus
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
Requested Permissions
27 permissionsAccess and modify data on every website you visit
Manage other installed extensions
Intercept, modify, and block all network requests
Block network requests before they complete
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The Adblock Plus extension for Firefox has been analyzed, and the findings suggest that it is a legitimate ad blocker with no malicious intentions. The extension's manifest declares potentially sensitive permissions such as <all_urls> and tabs, which is expected for an ad blocker. The network findings show multiple fetch and xmlhttprequest calls, which are likely used for updating the extension's blocklists and reporting issues. The background.js file is responsible for most of the network activity, which is consistent with the extension's functionality. The lack of malware signatures, obfuscation, and suspicious domains suggests that the extension is not malicious. One potential counterargument is that the extension's high user count and lack of developer name could indicate a potential security risk. However, the extension's functionality and network activity are consistent with its intended purpose, and there is no evidence to suggest that it is being used for malicious purposes. In fact, the extension's description and functionality are consistent with a legitimate ad blocker, and the network activity is likely necessary for the extension to function properly. For example, the NET-FETCH-background.js-52792 finding shows a fetch call being made, which is likely used to update the extension's blocklists. Similarly, the NET-XMLHTTPREQUEST-issue-reporter.js-7274 finding shows an xmlhttprequest call being made, which is likely used to report issues with the extension. Overall, the evidence suggests that Adblock Plus is a legitimate extension with no malicious intentions. The extension's functionality and network activity are consistent with its intended purpose, and there is no evidence to suggest that it is being used for malicious purposes. The lack of malware signatures, obfuscation, and suspicious domains further supports this conclusion. Therefore, it is likely that the extension is not malicious, and the findings are likely the result of its legitimate functionality. The extension's high user count and lack of developer name do not necessarily indicate a security risk, as the extension's functionality and network activity are consistent with its intended purpose. In conclusion, the analysis suggests that Adblock Plus is a legitimate extension with no malicious intentions, and the findings are likely the result of its legitimate functionality. The extension's functionality and network activity are consistent with its intended purpose, and there is no evidence to suggest that it is being used for malicious purposes. The lack of malware signatures, obfuscation, and suspicious domains further supports this conclusion. The extension's high user count and lack of developer name do not necessarily indicate a security risk, as the extension's functionality and network activity are consistent with its intended purpose. The extension's description and functionality are consistent with a legitimate ad blocker, and the network activity is likely necessary for the extension to function properly. Therefore, it is likely that the extension is not malicious, and the findings are likely the result of its legitimate functionality.
Key Reasons
- No malware signatures matched
- No obfuscation detected
- No suspicious domains found
False Positive Considerations
- IoC extractor garbage
- YARA code-smell rules
Reviewed 2026-05-23; recommended action: no action; model confidence 90%.
Firefox version history
Risk trend by version
11 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
VaultysHub extension
Vaultys
Kindredly - A safer, private web for families
Kindredly.ai
Malwarebytes Browser Guard
Malwarebytes
VHS - Dev Tools
Vihat Software
Ultimate New Tab Page - AI Search & Dial
Dracon
General Sticker System (GSS)
ElfinL