Firefox Add-ons

uBO-Scope

by Raymond Hill · 820 users · 4.8 rating
ae0be1d4-b45d-5948-a40b-d2a9ad0b81e8 | v1.5.1
59/ 100
MEDIUM risk
No change since v1.5.0
Risk verdict
Review before use

Score-based assessment (medium risk, 59/100). Last analyst review covers version 1.5.0.

Analysis record

Analysed
6 days ago
Version
v1.5.1
Artifact
SHA256 152…A78
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

32 detail rows

YARA Rule Matches

8 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall file download 4
js/lib/publicsuffixlist.jsjs/popup.jsassets/thirdparties/publicsuffix.org/list/public_suffix_list.dat +1 more
-
LOWpostinstall crypto operations 3
js/popup.jsassets/thirdparties/publicsuffix.org/list/public_suffix_list.datjs/lib/s14e-serializer.js
-
LOWpostinstall system command 3
LICENSE.txtassets/thirdparties/publicsuffix.org/list/public_suffix_list.datjs/background.js
-
LOWpostinstall file manipulation 6
js/dom.jsjs/popup.jsjs/ext.js +3 more
-
LOWpostinstall network communication 8
js/background.jspopup.htmlimg/ubo-scope.svg +5 more
-
LOWpostinstall environment access 1
css/fonts/Inter/LICENSE.txt
-
LOWpostinstall registry modification 2
css/popup.cssassets/thirdparties/publicsuffix.org/list/public_suffix_list.dat
-
LOWpostinstall obfuscation 3
js/lib/publicsuffixlist.jsjs/lib/punycode.es6.jsjs/lib/s14e-serializer.js
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

9,700 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

Raymond Hill

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

34
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Limited signal
Limited
Extension portfolio
5
Portfolio

12 evidence rows available.

Finding Categories

2
Network
9,700
IoC Indicators

YARA Rules Matched

8 rules(30 hits)
postinstall file download postinstall crypto operations postinstall system command postinstall file manipulation postinstall network communication postinstall environment access postinstall registry modification postinstall obfuscation

Requested Permissions

9 permissions
https://*/*
Dangerous
http://*/*
Dangerous
wss://*/*
Dangerous
ws://*/*
Dangerous
webRequest

Intercept, modify, and block all network requests

High
activeTab
Medium
scripting
Low
storage
Low
webNavigation
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality weak.

Security Analysis: uBO-Scope

Scan Results

The CVEQ analysis for this Firefox extension returned zero security findings across all categories. The findings_by_category field is completely empty, indicating no detections for network indicators of compromise (IoCs), YARA code-smell patterns, obfuscation techniques, malware signatures, or suspicious domains. This absence of findings is unusual and requires clarification. Either the extension is genuinely clean with no security concerns, or the scanning process did not execute properly.

Developer Attribution Gap

The extension lists an empty developer_name field. This is a significant information gap because legitimate extensions typically have identifiable publishers, anonymous attribution prevents verification of developer history, and it's impossible to cross-reference this extension against known publishers or their other products.

Naming Convention Analysis

The extension name "uBO-Scope" resembles "uBlock Origin" (commonly abbreviated as uBO), a legitimate and widely-trusted privacy extension. This naming could indicate a legitimate companion tool for uBlock Origin users, potential typosquatting to leverage uBlock Origin's reputation, or an unrelated extension using similar terminology. Without additional context or developer information, this remains ambiguous.

User Base

The extension has 790 users on Firefox, indicating moderate adoption. This user count alone is neither a positive nor negative security signal.

Counterargument

A skeptic might argue that zero findings indicates a clean extension that requires no action. This reasoning has merit if the scan completed successfully. However, the combination of empty findings with missing developer attribution creates uncertainty. A clean scan from an anonymous developer is less trustworthy than one from a verified publisher. The absence of evidence is not evidence of absence.

Recommendation

Reanalysis is required to verify the scan completed properly and to attempt developer identification. If the reanalysis also returns zero findings, the extension may be safe, but the developer attribution gap should be addressed before widespread adoption.

Key Reasons

  • Zero security findings across all scan categories
  • Missing developer attribution
  • Name resembles uBlock Origin without confirmed relationship

Reviewed 2026-04-23; recommended action: reanalyze; model confidence 60%.

Firefox version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
59
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
1.5.0
Apr 3, 2026
Risk range
59 to 59
Across analyzed versions
Latest analyzed version
1.5.1
Sep 25, 2026
Selected version
medium
Version
v1.5.1
6 days ago
Risk score
59
Findings
9732
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

A simple extension which primary purpose is to reveal all the connections -- attempted or successful -- to remote servers. <strong>Important:</strong> The badge count on the toolbar icon reports <strong>the number of distinct third-party remote servers for which there was a connection</strong>. Therefore a lower count is more desirable than a higher one. Keep in mind that not all third party remote servers are necessarily to be avoided, though the number of legitimate third parties are usually low count, typically CDNs. The extension uses <code>webRequest</code> listeners to report what exactly happened to network requests made by webpages. This extension is able to report the outcome of network requests regardless of which content blocker is in effect, including content blocking through DNS servers, as long as the browser reports network requests through its <code>webRequest</code> API. Network requests made outside the reach of the <code>webRequest</code> API cannot be reported by this extension.

Frequently Asked Questions