Is Adblock for Youtube™ safe?

High risk

Adblock for Youtube™ fetches remotely-controlled blocking rules and scriptlets from its own servers on every startup.

On each startup, the extension pulls network rules, CSS rules, popup config, and scriptlets from api.adblock-for-youtube.com. These server-supplied scriptlets are injected into web pages via chrome.scripting, meaning the server can change what code runs on any visited page without an extension update. On install, the extension opens a tab to get.adblock-for-youtube.com transmitting the extension ID and version, which together form a stable per-installation identifier.

AdBlock Ltd.v7.2.6Chrome Web Store
75Risk
Who publishes it

AdBlock Ltd. - no other listings under this identity, 2 shared hostnames

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
AdBlock Ltd.
Declared legal entity
AdBlock Ltd.
Registered address
International House, Mdina Road, Mriehel, Birkirkara BKR 3000, MT

Shared hosts - 2 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

api.adblock-for-youtube.com
Also called by 3 other listings, including Adblock for Youtube™
get.adblock-for-youtube.com
Also called by 4 other listings, including Adblock for Youtube™

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-829
SourceAI SANDBOX

Server-controlled scriptlet injection on every startup

Every time your browser starts, Adblock for Youtube downloads fresh rules from its server, including "scriptlets": small JS programs injected into every YouTube page.

The server can swap scriptlets for any code, anytime, no update needed.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open your browser.

The extension service worker starts automatically in the background.

The extension did this

The extension fetches fresh rules from its own server without a consent prompt and injects JavaScript into every YouTube tab.

The server-supplied scriptlets run in the page's MAIN world, the same trust level as YouTube's own code.

02EvidenceNETWORK CAPTURE
Captured request
GEThttps://api.adblock-for-youtube.com/api/v2/rules?version=7.0.8
200 OK, 1507ms, JSON body containing networkRules (46 entries), cssRules (16 entries), scripletsRules, popupConfig
03EvidenceFIELD TABLE
What the server delivers in the response
FieldValueWhy it matters
Scriptlets
abort-on-property-read.js youtube.ads.enabledSmall JavaScript programs the extension runs inside every YouTube tab you visit. The server decides what these do.
Network blocking rules
||youtube.com/pagead/URLs the extension will block on your behalf. Any ad server, or any other site, can be added or removed without a consent prompt.
CSS hiding rules
ytd-display-ad-rendererCSS selectors used to hide elements on YouTube pages. Can be used to hide any content, not just ads.
Popup config
{"showRating": true, "ratingDelay": 7}Controls what notifications and prompts appear in the extension popup. The server can change what you see.
04EvidenceCODE COMPARE
The code that does this

fetchServerData(), the outbound call

What it actually does
Readable equivalent
// Fetches rules from the remote server on every service worker start
async function fetchServerData() {
    try {
        const response = await fetch(
            `https://api.adblock-for-youtube.com/api/v2/rules?version=${EXTENSION_VERSION}`
        );
        return await response.json();
        // Returns: { networkRules, cssRules, popupConfig, scripletsRules, updatePageConfig }
    } catch (e) {
        console.log(e);
        return null;
    }
}
05EvidenceCODE COMPARE
The code that does this

executeScriptOnPage(), scriptlet injection into MAIN world

What it actually does
Readable equivalent
// Injects server-controlled scriptlets into a YouTube tab
async function executeScriptOnPage(tabId, script) {
    // Wraps the server-supplied code in an IIFE with error suppression
    const injectionString = `(()=>{ try { ${script}; } catch(e) { console.log(e) } })();`;
    await chrome.scripting.executeScript({
        target: { tabId },
        func: injectedFunction,
        injectImmediately: true,
        world: 'MAIN',       // runs with same privileges as the page itself
        args: [injectionString, 'aby-38oj8EJVO3Uu7t4G9PdfI'],
    });
}

// Called on every tab load — combines server scriptlets with hardcoded inline scripts
async function getScriptsAndInject(tabId) {
    const scriptlets = getScriptletString(Settings[SettingsKeys.ScripletsRules]); // from remote fetch
    const inlineScripts = inlineScriptsArray.join(';');
    await executeScriptOnPage(tabId, scriptlets + inlineScripts);
}
06EvidenceTHIRD PARTY LIST
Remote infrastructure used for rule delivery
  • api.adblock-for-youtube.com

    Rule delivery endpoint. Returns networkRules, cssRules, scripletsRules, and popupConfig on every SW start. Operator-controlled; updates take effect immediately, no update needed.

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Extension ID Transmitted to Developer Server on Install

On install, Adblock for Youtube opens a tab to its server, passing the extension's ID and version in the URL.

Testing captured Chrome navigating to adblock-for-y.com/install-v20?v=7.0.8&xtid=<id>; xtid is a stable, persistent identifier.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You install Adblock for Youtube from the Chrome Web Store.

The extension did this

The extension opens a new browser tab to the developer's server, passing your unique extension ID and the extension version in the URL.

This happens automatically on first install, without a user prompt. The same notification fires for updates and uninstall.

02EvidenceNETWORK CAPTURE
Captured request
GEThttps://adblock-for-y.com/install-v20?v=7.0.8&xtid=cmedhionkhpnakcndndgjdbohmhepckk
HTTP 200. Page title: 'Adblock for Youtube extension successfully installed'. Observed in our dynamic analysis session immediately after fresh install.
03EvidenceFIELD TABLE
What the install URL transmits to the developer's server:
FieldValueWhy it matters
Your extension ID (xtid)
cmedhionkhpnakcndndgjdbohmhepckkA stable identifier for your install, unchanged across restarts, linking install/update/uninstall events to the same device.
Extension version (v)
7.0.8Which version of the extension you installed. Combined with the extension ID, it tells the server exactly which build you are running.
04EvidenceCODE COMPARE
The code that does this

The code that constructs and sends the install URL, from the extension's shipping source.

What it actually does
URL construction (readable)
// Values read at extension load time — before any user interaction.
const EXTENSION_VERSION = chrome.runtime.getManifest().version;  // e.g. "7.0.8"
const EXTENSION_ID      = chrome.runtime.id;                      // e.g. "cmedhionkhpnakcndndgjdbohmhepckk"

const INSTALL_URL   = `https://get.adblock-for-youtube.com/install?v=${EXTENSION_VERSION}&xtid=${EXTENSION_ID}`;
const UNINSTALL_URL = `https://get.adblock-for-youtube.com/uninstall?v=${EXTENSION_VERSION}&xtid=${EXTENSION_ID}`;
const UPDATE_URL    = `https://get.adblock-for-youtube.com/update?v=${EXTENSION_VERSION}&xtid=${EXTENSION_ID}`;
Install + uninstall handlers (readable)
// Runs once when the extension is first installed.
chrome.runtime.onInstalled.addListener(({ reason }) => {
  if (reason === chrome.runtime.OnInstalledReason.INSTALL) {
    // Opens a visible tab — the URL contains the extension ID.
    await createTab(INSTALL_URL);
  }
});

// Registers the uninstall URL so the server is notified on removal.
chrome.runtime.setUninstallURL(UNINSTALL_URL);

// On the first startup AFTER an update, opens a tab to the update URL.
chrome.runtime.onStartup.addListener(async () => {
  const showUpdate = await getFromChromeStorage('ShowUpdatePageNextLaunch');
  if (showUpdate) {
    await createTab(UPDATE_URL);  // also contains xtid + new version
  }
});
05EvidenceTHIRD PARTY LIST
Servers that receive the install notification:
  • get.adblock-for-youtube.com

    Developer-owned server. Receives the install, update, and uninstall events with the extension ID and version in the URL query string.

  • adblock-for-y.com

    Appears to be a short-link or redirect alias for the same developer infrastructure. Testing observed the final page load here after the redirect from get.adblock-for-youtube.com.

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-829
SourceAI SANDBOX

Remote-controlled scriptlets injected into every page you visit

On each page load, Adblock for Youtube fetches scriptlet rules from its server and runs them via Chrome's scripting API.

Testing captured 11 scriptlets from api.adblock-for-youtube.com and 7 executeScript calls into a YouTube MAIN world.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You navigate to any website.

The extension's content-script pattern matches all http and https URLs, so every page load triggers scriptlet injection.

The extension did this

The extension runs JavaScript code whose content and arguments are determined by a remote server.

The background service worker fetches a scriptlet ruleset from api.adblock-for-youtube.com, compiles each rule into a JavaScript function call, and executes the result in the page's MAIN world via chrome.scripting.executeScript.

02EvidenceNETWORK CAPTURE
Captured request
GEThttps://api.adblock-for-youtube.com/api/v2/rules?version=7.2.2
JSON object containing networkRules, cssRules, popupConfig, scripletsRules (11 entries), and updatePageConfig. The scripletsRules array was stored in chrome.storage.local and subsequently injected into page contexts.
03EvidenceSTORAGE DUMP
Unknown block kind: storage_dump

The data has shipped a block kind this view doesn't render yet. Raw payload below.

{
  "kind": "storage_dump",
  "location": "chrome.storage.local key 'scripletsRules'",
  "contents": "",
  "meaning": "The 11 server-controlled scriptlets observed in testing. The server can change any entry without an update; changes apply on the next fetch.",
  "technicalNote": "Stored under SettingsKeys.ScripletsRules ('scripletsRules'). Retrieved from api.adblock-for-youtube.com/api/v2/rules response field 'scripletsRules'. Background service worker reads this on every page navigation via getScriptsAndInject()."
}
04EvidenceCODE COMPARE
The code that does this

Server rules compiled and injected into page MAIN world

What it actually does
What the scriptlet pipeline does, plainly
// On each page navigation:
// 1. Read scripletsRules from chrome.storage (populated from server)
// 2. For each rule {name, args}, look up the scriptlet function body
//    from the embedded scriptletsLib catalogue
// 3. Assemble: `(scriptletFunction)(source, args)` strings, join with ';'
// 4. Wrap in an IIFE and inject via chrome.scripting.executeScript
//    into world:'MAIN' — the page's own JavaScript context
//
// The server controls: which scriptlet names appear, and their args.
// The scriptlet function bodies are bundled in the extension.
// Example observed rule: {name:'set-constant', args:['ytInitialPlayerResponse.adPlacements','undefined']}
// → injects code that overwrites window.ytInitialPlayerResponse.adPlacements = undefined
05EvidenceTHIRD PARTY LIST
Scriptlet ruleset origin
  • api.adblock-for-youtube.com

    Extension-operated API server. Provides the scripletsRules array injected into every page. The operator controls invocations/arguments served to all installs, without an update.

Where it sends data

Destinations our analysis observed Adblock for Youtube contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • api.adblock-for-youtube.com

    Adblock for Youtube sends data to api.adblock-for-youtube.com. One other extension we have analysed sends data here.

  • get.adblock-for-youtube.com

    Adblock for Youtube sends data to get.adblock-for-youtube.com. No other extension we have analysed sends data here.

Updated 30 September 2026cmedhionkhpnakcndndgjdbohmhepckk