uBO-Scope
Score-based assessment (medium risk, 59/100). Last analyst review covers version 1.5.0.
Analysis record
- Analysed
- 6 days ago
- Version
- v1.5.1
- Artifact
- SHA256 152…A78
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
8 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall file download | 4 | js/lib/publicsuffixlist.jsjs/popup.jsassets/thirdparties/publicsuffix.org/list/public_suffix_list.dat +1 more | - |
| LOW | postinstall crypto operations | 3 | js/popup.jsassets/thirdparties/publicsuffix.org/list/public_suffix_list.datjs/lib/s14e-serializer.js | - |
| LOW | postinstall system command | 3 | LICENSE.txtassets/thirdparties/publicsuffix.org/list/public_suffix_list.datjs/background.js | - |
| LOW | postinstall file manipulation | 6 | js/dom.jsjs/popup.jsjs/ext.js +3 more | - |
| LOW | postinstall network communication | 8 | js/background.jspopup.htmlimg/ubo-scope.svg +5 more | - |
| LOW | postinstall environment access | 1 | css/fonts/Inter/LICENSE.txt | - |
| LOW | postinstall registry modification | 2 | css/popup.cssassets/thirdparties/publicsuffix.org/list/public_suffix_list.dat | - |
| LOW | postinstall obfuscation | 3 | js/lib/publicsuffixlist.jsjs/lib/punycode.es6.jsjs/lib/s14e-serializer.js | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidenceRaymond Hill
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
YARA Rules Matched
8 rules(30 hits)Requested Permissions
9 permissionsIntercept, modify, and block all network requests
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality weak.
Security Analysis: uBO-Scope
Scan Results
The CVEQ analysis for this Firefox extension returned zero security findings across all categories. The findings_by_category field is completely empty, indicating no detections for network indicators of compromise (IoCs), YARA code-smell patterns, obfuscation techniques, malware signatures, or suspicious domains. This absence of findings is unusual and requires clarification. Either the extension is genuinely clean with no security concerns, or the scanning process did not execute properly.
Developer Attribution Gap
The extension lists an empty developer_name field. This is a significant information gap because legitimate extensions typically have identifiable publishers, anonymous attribution prevents verification of developer history, and it's impossible to cross-reference this extension against known publishers or their other products.
Naming Convention Analysis
The extension name "uBO-Scope" resembles "uBlock Origin" (commonly abbreviated as uBO), a legitimate and widely-trusted privacy extension. This naming could indicate a legitimate companion tool for uBlock Origin users, potential typosquatting to leverage uBlock Origin's reputation, or an unrelated extension using similar terminology. Without additional context or developer information, this remains ambiguous.
User Base
The extension has 790 users on Firefox, indicating moderate adoption. This user count alone is neither a positive nor negative security signal.
Counterargument
A skeptic might argue that zero findings indicates a clean extension that requires no action. This reasoning has merit if the scan completed successfully. However, the combination of empty findings with missing developer attribution creates uncertainty. A clean scan from an anonymous developer is less trustworthy than one from a verified publisher. The absence of evidence is not evidence of absence.
Recommendation
Reanalysis is required to verify the scan completed properly and to attempt developer identification. If the reanalysis also returns zero findings, the extension may be safe, but the developer attribution gap should be addressed before widespread adoption.
Key Reasons
- Zero security findings across all scan categories
- Missing developer attribution
- Name resembles uBlock Origin without confirmed relationship
Reviewed 2026-04-23; recommended action: reanalyze; model confidence 60%.
Firefox version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
uBlock Origin Lite
Raymond Hill
uBlock Origin
Raymond Hill
JSaw Puzzle
Raymond Hill
VaultysHub extension
Vaultys
Kindredly - A safer, private web for families
Kindredly.ai
Malwarebytes Browser Guard
Malwarebytes