Is Adblock for Youtube™ safe?
Adblock for Youtube™ fetches remotely-controlled blocking rules and scriptlets from its own servers on every startup.
On each startup, the extension pulls network rules, CSS rules, popup config, and scriptlets from api.adblock-for-youtube.com. These server-supplied scriptlets are injected into web pages via chrome.scripting, meaning the server can change what code runs on any visited page without an extension update. On install, the extension opens a tab to get.adblock-for-youtube.com transmitting the extension ID and version, which together form a stable per-installation identifier.
Who publishes itAdBlock Ltd. - no other listings under this identity, 2 shared hostnames
AdBlock Ltd. - no other listings under this identity, 2 shared hostnames
What this publisher told the store about itself, and the other listings that told it the same thing.
Shared hosts - 2 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Server-controlled scriptlet injection on every startup
Every time your browser starts, Adblock for Youtube downloads fresh rules from its server, including "scriptlets": small JS programs injected into every YouTube page.
The server can swap scriptlets for any code, anytime, no update needed.
You open your browser.
The extension service worker starts automatically in the background.
The extension fetches fresh rules from its own server without a consent prompt and injects JavaScript into every YouTube tab.
The server-supplied scriptlets run in the page's MAIN world, the same trust level as YouTube's own code.
| Field | Value | Why it matters | |
|---|---|---|---|
Scriptlets | abort-on-property-read.js youtube.ads.enabled | Small JavaScript programs the extension runs inside every YouTube tab you visit. The server decides what these do. | |
Network blocking rules | ||youtube.com/pagead/ | URLs the extension will block on your behalf. Any ad server, or any other site, can be added or removed without a consent prompt. | |
CSS hiding rules | ytd-display-ad-renderer | CSS selectors used to hide elements on YouTube pages. Can be used to hide any content, not just ads. | |
Popup config | {"showRating": true, "ratingDelay": 7} | Controls what notifications and prompts appear in the extension popup. The server can change what you see. |
fetchServerData(), the outbound call
// Fetches rules from the remote server on every service worker start
async function fetchServerData() {
try {
const response = await fetch(
`https://api.adblock-for-youtube.com/api/v2/rules?version=${EXTENSION_VERSION}`
);
return await response.json();
// Returns: { networkRules, cssRules, popupConfig, scripletsRules, updatePageConfig }
} catch (e) {
console.log(e);
return null;
}
}executeScriptOnPage(), scriptlet injection into MAIN world
// Injects server-controlled scriptlets into a YouTube tab
async function executeScriptOnPage(tabId, script) {
// Wraps the server-supplied code in an IIFE with error suppression
const injectionString = `(()=>{ try { ${script}; } catch(e) { console.log(e) } })();`;
await chrome.scripting.executeScript({
target: { tabId },
func: injectedFunction,
injectImmediately: true,
world: 'MAIN', // runs with same privileges as the page itself
args: [injectionString, 'aby-38oj8EJVO3Uu7t4G9PdfI'],
});
}
// Called on every tab load — combines server scriptlets with hardcoded inline scripts
async function getScriptsAndInject(tabId) {
const scriptlets = getScriptletString(Settings[SettingsKeys.ScripletsRules]); // from remote fetch
const inlineScripts = inlineScriptsArray.join(';');
await executeScriptOnPage(tabId, scriptlets + inlineScripts);
}- api.adblock-for-youtube.com
Rule delivery endpoint. Returns networkRules, cssRules, scripletsRules, and popupConfig on every SW start. Operator-controlled; updates take effect immediately, no update needed.
Extension ID Transmitted to Developer Server on Install
On install, Adblock for Youtube opens a tab to its server, passing the extension's ID and version in the URL.
Testing captured Chrome navigating to adblock-for-y.com/install-v20?v=7.0.8&xtid=<id>; xtid is a stable, persistent identifier.
You install Adblock for Youtube from the Chrome Web Store.
The extension opens a new browser tab to the developer's server, passing your unique extension ID and the extension version in the URL.
This happens automatically on first install, without a user prompt. The same notification fires for updates and uninstall.
| Field | Value | Why it matters | |
|---|---|---|---|
Your extension ID (xtid) | cmedhionkhpnakcndndgjdbohmhepckk | A stable identifier for your install, unchanged across restarts, linking install/update/uninstall events to the same device. | |
Extension version (v) | 7.0.8 | Which version of the extension you installed. Combined with the extension ID, it tells the server exactly which build you are running. |
The code that constructs and sends the install URL, from the extension's shipping source.
// Values read at extension load time — before any user interaction.
const EXTENSION_VERSION = chrome.runtime.getManifest().version; // e.g. "7.0.8"
const EXTENSION_ID = chrome.runtime.id; // e.g. "cmedhionkhpnakcndndgjdbohmhepckk"
const INSTALL_URL = `https://get.adblock-for-youtube.com/install?v=${EXTENSION_VERSION}&xtid=${EXTENSION_ID}`;
const UNINSTALL_URL = `https://get.adblock-for-youtube.com/uninstall?v=${EXTENSION_VERSION}&xtid=${EXTENSION_ID}`;
const UPDATE_URL = `https://get.adblock-for-youtube.com/update?v=${EXTENSION_VERSION}&xtid=${EXTENSION_ID}`;// Runs once when the extension is first installed.
chrome.runtime.onInstalled.addListener(({ reason }) => {
if (reason === chrome.runtime.OnInstalledReason.INSTALL) {
// Opens a visible tab — the URL contains the extension ID.
await createTab(INSTALL_URL);
}
});
// Registers the uninstall URL so the server is notified on removal.
chrome.runtime.setUninstallURL(UNINSTALL_URL);
// On the first startup AFTER an update, opens a tab to the update URL.
chrome.runtime.onStartup.addListener(async () => {
const showUpdate = await getFromChromeStorage('ShowUpdatePageNextLaunch');
if (showUpdate) {
await createTab(UPDATE_URL); // also contains xtid + new version
}
});- get.adblock-for-youtube.com
Developer-owned server. Receives the install, update, and uninstall events with the extension ID and version in the URL query string.
- adblock-for-y.com
Appears to be a short-link or redirect alias for the same developer infrastructure. Testing observed the final page load here after the redirect from get.adblock-for-youtube.com.
Remote-controlled scriptlets injected into every page you visit
On each page load, Adblock for Youtube fetches scriptlet rules from its server and runs them via Chrome's scripting API.
Testing captured 11 scriptlets from api.adblock-for-youtube.com and 7 executeScript calls into a YouTube MAIN world.
You navigate to any website.
The extension's content-script pattern matches all http and https URLs, so every page load triggers scriptlet injection.
The extension runs JavaScript code whose content and arguments are determined by a remote server.
The background service worker fetches a scriptlet ruleset from api.adblock-for-youtube.com, compiles each rule into a JavaScript function call, and executes the result in the page's MAIN world via chrome.scripting.executeScript.
storage_dumpThe data has shipped a block kind this view doesn't render yet. Raw payload below.
{
"kind": "storage_dump",
"location": "chrome.storage.local key 'scripletsRules'",
"contents": "",
"meaning": "The 11 server-controlled scriptlets observed in testing. The server can change any entry without an update; changes apply on the next fetch.",
"technicalNote": "Stored under SettingsKeys.ScripletsRules ('scripletsRules'). Retrieved from api.adblock-for-youtube.com/api/v2/rules response field 'scripletsRules'. Background service worker reads this on every page navigation via getScriptsAndInject()."
}Server rules compiled and injected into page MAIN world
// On each page navigation:
// 1. Read scripletsRules from chrome.storage (populated from server)
// 2. For each rule {name, args}, look up the scriptlet function body
// from the embedded scriptletsLib catalogue
// 3. Assemble: `(scriptletFunction)(source, args)` strings, join with ';'
// 4. Wrap in an IIFE and inject via chrome.scripting.executeScript
// into world:'MAIN' — the page's own JavaScript context
//
// The server controls: which scriptlet names appear, and their args.
// The scriptlet function bodies are bundled in the extension.
// Example observed rule: {name:'set-constant', args:['ytInitialPlayerResponse.adPlacements','undefined']}
// → injects code that overwrites window.ytInitialPlayerResponse.adPlacements = undefined- api.adblock-for-youtube.com
Extension-operated API server. Provides the scripletsRules array injected into every page. The operator controls invocations/arguments served to all installs, without an update.
Where it sends data
Destinations our analysis observed Adblock for Youtube contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- api.adblock-for-youtube.com
Adblock for Youtube sends data to api.adblock-for-youtube.com. One other extension we have analysed sends data here.
- get.adblock-for-youtube.com
Adblock for Youtube sends data to get.adblock-for-youtube.com. No other extension we have analysed sends data here.