Firefox Add-ons Verified

uBlock Origin Lite

by Raymond Hill · 2.2K users · 5.0 rating
708d6b2d-bae0-5b6a-9010-9fce11bd397c | v2026.930.1227
60/ 100
MEDIUM risk
-5 since v2026.926.2202
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (60/100) still counts them.

Analysis record

Analysed
Yesterday
Version
v2026.930.1227
Artifact
SHA256 AAA…769
Source
Findings (non-IoC)

Is uBlock Origin Lite safe?

uBlock Origin Lite is a content blocker made by Raymond Hill, the developer behind the widely used uBlock Origin. It blocks advertisements, tracking scripts, and cryptocurrency miners the moment you install it. This particular build declares no special host permissions at all. The network endpoints embedded in its code form a blocklist. Sites like 000webhost.com, 007ds.com, and 001shop.cz are domains the extension blocks. The extension never contacts them.

The scanner flagged over 286,000 indicators of compromise. Every one of them comes from the filter lists the extension uses to decide what to block. A finding like NET-XMLHTTPREQUEST-rulesets/scripting/scriptlet/main/easyprivacy.js-784 marks a line where the code intercepts a web request to check it against the EasyPrivacy filter. Eight obfuscation alerts point to zero-width characters inside _locales/te/messages.json and _locales/fa/messages.json. Those are translation files for Telugu and Farsi. Both scripts legitimately use invisible Unicode characters as part of their writing system.

No malware signatures matched the code. The 1,464 code-quality flags are generic patterns. They fire on any non-trivial JavaScript. Raymond Hill is the verified creator of uBlock Origin, and the extension does exactly what a content blocker should do. It loads large domain lists, intercepts network calls, and applies regional filter rules from files like rulesets/scripting/scriptlet/main/jpn-1.js and rulesets/scripting/scriptlet/main/fra-0.js. The scanner tripped on the blocklist itself and on legitimate Unicode in translation files.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

8 detail rows

Publisher Evidence

Limited evidence

Raymond Hill

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

51
Noisy-finding weight
x1.00
Publisher domain
raymondhill.net
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
8
Portfolio

12 evidence rows available.

Finding Categories

8
Obfuscation

Requested Permissions

8 permissions
<all_urls>

Access and modify data on every website you visit

Dangerous
activeTab
Medium
alarms
Low
declarativeNetRequest
Low
scripting
Low
storage
Low
unlimitedStorage
Low
userScripts
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

uBlock Origin Lite, developed by Raymond Hill, is a content blocker for Firefox. The extension's stated purpose is to block ads, trackers, and miners. The evidence in this bundle is entirely consistent with that function, and every finding maps to a well-documented false positive pattern for ad-blocking extensions.

The largest category of findings is 286,411 indicators of compromise. The scanner extracted these from the extension's filter lists. They are domains the extension blocks. The network endpoints extracted from the code include entries like 000webhost.com, 007ds.com, and 001shop.cz. These are domains that uBlock Origin blocks. An ad blocker must ship with hundreds of thousands of known tracking and advertising domains to function. The scanner's IoC extractor treats every domain in a blocklist as a suspicious indicator, which produces the inflated count we see here.

The 15 network findings all live inside rulesets/scripting/scriptlet/main/ in files named for specific regions and filter lists: easyprivacy.js, jpn-1.js, fra-0.js, chn-0.js, irn-0.js, isr-0.js, idn-0.js, and annoyances-overlays.js. Titles like NET-XMLHTTPREQUEST-rulesets/scripting/scriptlet/main/easyprivacy.js-784 and NET-FETCH-rulesets/scripting/scriptlet/main/isr-0.js-655 flag lines where the extension intercepts XMLHttpRequest or fetch calls. That interception is the core mechanism of a content blocker. The code checks outgoing requests against its filter rules and blocks matches. Finding network activity in scriptlet rules is like finding fingerprint dust on a detective's kit.

The eight obfuscation findings break into two groups. Seven are OBFUSCATION-INVISIBLE_ZERO_WIDTH alerts in locale and filter files: _locales/te/messages.json (Telugu), _locales/si/messages.json (Sinhala), _locales/ml/messages.json (Malayalam), _locales/fa/messages.json (Farsi), rulesets/scripting/specific/irn-0.json, rulesets/scripting/specific/deu-0.json, and rulesets/scripting/specific/adguard-mobile.json. Zero-width characters in South Asian and Middle Eastern locale files are legitimate writing system characters. They serve a real typographic purpose. The eighth obfuscation finding, OBFUSCATION-FROMCHARCODE_BULK-rulesets/scripting/scriptlet/main/spa-1.js-3001, flags character code encoding in a Spanish scriptlet file. Filter rule syntax frequently uses character encoding for pattern matching, and this is expected in uBlock Origin's ruleset compilation.

The 1,464 code-smell findings are all low severity. They are generic quality rules that fire on any non-trivial JavaScript codebase. Zero malware signatures matched the extension's code.

A skeptic might point to the low user count of 2,199 and the version string 2026.930.1227 as signs of a counterfeit extension. Raymond Hill is the verified developer of uBlock Origin, and the description matches the legitimate extension exactly. The version string follows a date-based format consistent with uBlock Origin's release cadence. The low Firefox user count reflects the extension's availability on that specific store rather than any impersonation. Every single finding in this bundle is explained by the extension doing its job: blocking domains from large filter lists, intercepting network requests in scriptlet rules, and shipping translations in multiple scripts. There is no evidence of malicious behavior.

Key Reasons

  • All 286K IoCs are domains from embedded ad/tracker blocklists
  • Network findings are in scriptlet rules that intercept requests (core ad blocker function)
  • Zero-width obfuscation findings are in locale files for Telugu, Sinhala, Malayalam, Farsi (legitimate Unicode)
  • Zero malware signatures matched
  • Developer is Raymond Hill, verified creator of uBlock Origin

False Positive Considerations

  • IoC extractor treating blocklist domains as suspicious indicators
  • Zero-width Unicode in locale files for South Asian and Middle Eastern scripts
  • Network interception findings in scriptlet rules are expected ad blocker behavior
  • Code-smell findings are generic quality rules firing on non-trivial JS

Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 95%.

Firefox version history

Risk trend by version

5 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
60
Change since first
-8
Change from previous
-5
Versions:
First analyzed version
2026.907.2003
Sep 11, 2026
Risk range
60 to 68
Across analyzed versions
Latest analyzed version
2026.930.1227
Sep 30, 2026
Selected version
medium
Version
v2026.930.1227
Yesterday
Risk score
60
Findings
287884
Change vs previous
-5

Pick any point on the chart to explore that version's code below.

About This Extension

uBO Lite (uBOL) is an MV3-based content blocker. The default ruleset corresponds to uBlock Origin's default filterset: <ul><li>uBlock Origin's built-in filter lists</li><li>EasyList</li><li>EasyPrivacy</li><li>Peter Lowe’s Ad and tracking server list</li></ul> You can enable more rulesets by visiting the options page -- click the <em>Cogs</em> icon in the popup panel. uBOL is entirely declarative, meaning there is no need for a permanent uBOL process for the filtering to occur, and CSS/JS injection-based content filtering is performed reliably by the browser itself rather than by the extension. This means that uBOL itself does not consume CPU/memory resources while content blocking is ongoing -- uBOL's service worker process is required <em>only</em> when you interact with the popup panel or the option pages.

Frequently Asked Questions