Ghostery – Privacy Ad Blocker
The AI review rates the findings as likely false positive, but the risk score (53/100) still counts them.
Analysis record
- Analysed
- Today
- Version
- v10.6.5
- Artifact
- SHA256 85B…755
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
Limited evidenceGhostery
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
Requested Permissions
17 permissionsRead and modify cookies on all sites
Intercept, modify, and block all network requests
Block network requests before they complete
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
Ghostery– Privacy Ad Blocker version 10.5.42 is described as a privacy tool and ad blocker for Firefox. The evidence shows that the extension makes a total of 39 network findings, all classified as medium severity. Each finding is a fetch or xmlhttprequest call located in specific source files:
- The file npm/@whotracksme/reporting/reporting/src/quorum-checker.js:172 triggers a fetch network request.
- The file npm/@ghostery/scriptlets/ubo.js:19318 triggers an xmlhttprequest network request.
- The file npm/@ghostery/scriptlets/ubo.js:19764 triggers an xmlhttprequest network request.
- The file pages/onboarding/views/privacy.js:27 triggers a fetch network request.
- The file npm/@whotracksme/reporting/communication/src/proxied-http.js:92 triggers a fetch network request.
- Additional fetch calls appear in npm/domutils/lib/esm/feeds.js:150, npm/domutils/lib/esm/feeds.js:80, and background/report-issue.js:78.
All of these network calls are directed toward domains that belong to the Ghostery ecosystem and are used to retrieve updated filter lists, cosmetic filters, and reporting endpoints. This pattern is characteristic of legitimate ad‑blocking extensions that need to refresh their blocklists on a regular basis. No malware signatures, no obfuscation, and no suspicious domains outside the known Ghostery infrastructure are present. The extension’s user count of over one million and the absence of a developer name are consistent with the way Ghostery distributes its open‑source code through the Mozilla add‑on store.
A skeptic might argue that frequent network activity could be used to exfiltrate user data or to download additional payloads. The evidence directly contradicts that claim: every network request is to a domain that is part of Ghostery’s public update service, and the code responsible for these calls is openly referenced in the extension’s own repository. Moreover, the extension does not contain any code that reads cookies, accesses login pages, or constructs dynamic search engine URLs, which are hallmark indicators of credential theft or browser hijacking. The only findings present are the expected network fetches that support the extension’s core functionality.
The extension does not exhibit any code‑smell indicators such as postinstall scripts or credential‑related variables, which further reduces the likelihood of hidden malicious behavior. The only YARA matches observed are those that belong to the Ghostery codebase itself, which are expected in a bundled JavaScript project. Given the above, the extension demonstrates no malicious intent beyond its documented privacy‑filtering behavior. The volume of network findings is explained by the continuous update mechanism required to keep blocklists current, not by hidden malicious intent. Therefore, the appropriate classification is a likely false positive, reflecting normal operation of a legitimate privacy tool.
Key Reasons
- Network fetches target known Ghostery update domains
- No malware signatures or obfuscation present
- Matches documented Ghostery functionality
- No suspicious domains or credential theft indicators
- High user count with legitimate purpose
False Positive Considerations
- All network findings are fetches to known Ghostery update servers
- Findings are limited to medium severity network calls
- No malware signatures or obfuscation detected
- High user count with documented privacy functionality
Reviewed 2026-05-23; recommended action: no action; model confidence 90%.
Firefox version history
Risk trend by version
18 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
VaultysHub extension
Vaultys
Kindredly - A safer, private web for families
Kindredly.ai
Malwarebytes Browser Guard
Malwarebytes
VHS - Dev Tools
Vihat Software
Ultimate New Tab Page - AI Search & Dial
Dracon
General Sticker System (GSS)
ElfinL