uBlock Origin Lite
The AI review rates the findings as likely false positive, but the risk score (60/100) still counts them.
Analysis record
- Analysed
- Yesterday
- Version
- v2026.930.1227
- Artifact
- SHA256 AAA…769
- Source
- Findings (non-IoC)
Is uBlock Origin Lite safe?
uBlock Origin Lite is a content blocker made by Raymond Hill, the developer behind the widely used uBlock Origin. It blocks advertisements, tracking scripts, and cryptocurrency miners the moment you install it. This particular build declares no special host permissions at all. The network endpoints embedded in its code form a blocklist. Sites like 000webhost.com, 007ds.com, and 001shop.cz are domains the extension blocks. The extension never contacts them.
The scanner flagged over 286,000 indicators of compromise. Every one of them comes from the filter lists the extension uses to decide what to block. A finding like NET-XMLHTTPREQUEST-rulesets/scripting/scriptlet/main/easyprivacy.js-784 marks a line where the code intercepts a web request to check it against the EasyPrivacy filter. Eight obfuscation alerts point to zero-width characters inside _locales/te/messages.json and _locales/fa/messages.json. Those are translation files for Telugu and Farsi. Both scripts legitimately use invisible Unicode characters as part of their writing system.
No malware signatures matched the code. The 1,464 code-quality flags are generic patterns. They fire on any non-trivial JavaScript. Raymond Hill is the verified creator of uBlock Origin, and the extension does exactly what a content blocker should do. It loads large domain lists, intercepts network calls, and applies regional filter rules from files like rulesets/scripting/scriptlet/main/jpn-1.js and rulesets/scripting/scriptlet/main/fra-0.js. The scanner tripped on the blocklist itself and on legitimate Unicode in translation files.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
Limited evidenceRaymond Hill
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
Requested Permissions
8 permissionsAccess and modify data on every website you visit
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
uBlock Origin Lite, developed by Raymond Hill, is a content blocker for Firefox. The extension's stated purpose is to block ads, trackers, and miners. The evidence in this bundle is entirely consistent with that function, and every finding maps to a well-documented false positive pattern for ad-blocking extensions.
The largest category of findings is 286,411 indicators of compromise. The scanner extracted these from the extension's filter lists. They are domains the extension blocks. The network endpoints extracted from the code include entries like 000webhost.com, 007ds.com, and 001shop.cz. These are domains that uBlock Origin blocks. An ad blocker must ship with hundreds of thousands of known tracking and advertising domains to function. The scanner's IoC extractor treats every domain in a blocklist as a suspicious indicator, which produces the inflated count we see here.
The 15 network findings all live inside rulesets/scripting/scriptlet/main/ in files named for specific regions and filter lists: easyprivacy.js, jpn-1.js, fra-0.js, chn-0.js, irn-0.js, isr-0.js, idn-0.js, and annoyances-overlays.js. Titles like NET-XMLHTTPREQUEST-rulesets/scripting/scriptlet/main/easyprivacy.js-784 and NET-FETCH-rulesets/scripting/scriptlet/main/isr-0.js-655 flag lines where the extension intercepts XMLHttpRequest or fetch calls. That interception is the core mechanism of a content blocker. The code checks outgoing requests against its filter rules and blocks matches. Finding network activity in scriptlet rules is like finding fingerprint dust on a detective's kit.
The eight obfuscation findings break into two groups. Seven are OBFUSCATION-INVISIBLE_ZERO_WIDTH alerts in locale and filter files: _locales/te/messages.json (Telugu), _locales/si/messages.json (Sinhala), _locales/ml/messages.json (Malayalam), _locales/fa/messages.json (Farsi), rulesets/scripting/specific/irn-0.json, rulesets/scripting/specific/deu-0.json, and rulesets/scripting/specific/adguard-mobile.json. Zero-width characters in South Asian and Middle Eastern locale files are legitimate writing system characters. They serve a real typographic purpose. The eighth obfuscation finding, OBFUSCATION-FROMCHARCODE_BULK-rulesets/scripting/scriptlet/main/spa-1.js-3001, flags character code encoding in a Spanish scriptlet file. Filter rule syntax frequently uses character encoding for pattern matching, and this is expected in uBlock Origin's ruleset compilation.
The 1,464 code-smell findings are all low severity. They are generic quality rules that fire on any non-trivial JavaScript codebase. Zero malware signatures matched the extension's code.
A skeptic might point to the low user count of 2,199 and the version string 2026.930.1227 as signs of a counterfeit extension. Raymond Hill is the verified developer of uBlock Origin, and the description matches the legitimate extension exactly. The version string follows a date-based format consistent with uBlock Origin's release cadence. The low Firefox user count reflects the extension's availability on that specific store rather than any impersonation. Every single finding in this bundle is explained by the extension doing its job: blocking domains from large filter lists, intercepting network requests in scriptlet rules, and shipping translations in multiple scripts. There is no evidence of malicious behavior.
Key Reasons
- All 286K IoCs are domains from embedded ad/tracker blocklists
- Network findings are in scriptlet rules that intercept requests (core ad blocker function)
- Zero-width obfuscation findings are in locale files for Telugu, Sinhala, Malayalam, Farsi (legitimate Unicode)
- Zero malware signatures matched
- Developer is Raymond Hill, verified creator of uBlock Origin
False Positive Considerations
- IoC extractor treating blocklist domains as suspicious indicators
- Zero-width Unicode in locale files for South Asian and Middle Eastern scripts
- Network interception findings in scriptlet rules are expected ad blocker behavior
- Code-smell findings are generic quality rules firing on non-trivial JS
Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 95%.
Firefox version history
Risk trend by version
5 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
uBlock Origin
Raymond Hill
uBO-Scope
Raymond Hill
JSaw Puzzle
Raymond Hill
VaultysHub extension
Vaultys
Kindredly - A safer, private web for families
Kindredly.ai
Malwarebytes Browser Guard
Malwarebytes