Is AdBlock Ninja – Block Ads, Boost Privacy, and Browse Faster safe?
AdBlock Ninja reads your precise device location and sends it to its own servers during account signup and social login.
When you create an account or sign in with Apple or Google in the extension's popup, AdBlock Ninja requests your precise geolocation and attaches your latitude and longitude to the request sent to its backend at api.adblockninja.com, alongside your login credentials or OAuth token. This happens automatically once location permission is granted and is not required to complete signup, so most users who allow the location prompt won't notice the data was sent. As an ad blocker, the extension has no stated feature that needs your location.
Who publishes itBirchwood Group, LLC - 6 other listings from the same operator, none carrying a finding
Birchwood Group, LLC - 6 other listings from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same operator - 6 listings
Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.
Shared hosts - 3 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
AdBlock Ninja attaches your precise GPS location to signup and login requests
Creating an account or signing in with Apple or Google prompts for your device's precise location, then attaches it to the request sent to the vendor's own server.
Code analysis shows this on an ad blocker with no location-based feature.
You fill in the signup form, or choose Sign in with Apple or Google, and submit.
The browser then shows its native location-permission prompt for the extension.
The popup reads your precise GPS coordinates and includes them in the same request as your account details.
This happens whether you are creating a new account or logging into an existing one.
Shared location helper, called from all three account flows
async function getLocation(timeoutMs = 3000) {
return new Promise((resolve) => {
if (!navigator.geolocation) return resolve(null);
const timeoutId = setTimeout(() => resolve(null), timeoutMs);
navigator.geolocation.getCurrentPosition(
(position) => {
clearTimeout(timeoutId);
resolve({ lat: position.coords.latitude, lng: position.coords.longitude });
},
() => { clearTimeout(timeoutId); resolve(null); },
{ enableHighAccuracy: true, timeout: timeoutMs }
);
});
}
// Called identically from registration, Apple login and Google login before
// each is POSTed to api.adblockninja.com.async function submit() {
await schema.validate(form);
const location = await getLocation();
if (location) form.location = JSON.stringify(location);
await axiosRequest.post('/users/register', form);
}async function sendTokenToServer(idToken) {
const location = await getLocation();
const payload = { id_token: idToken };
if (location) payload.location = JSON.stringify(location);
await axiosRequest.post('/auth/apple', payload);
}async function sendTokenToServer(idToken) {
const location = await getLocation();
const payload = { id_token: idToken };
if (location) payload.location = JSON.stringify(location);
await axiosRequest.post('/auth/google', payload);
}| Field | Value | Why it matters | |
|---|---|---|---|
Your GPS coordinates | {"lat":40.7306,"lng":-73.9352} | Precise latitude and longitude from the browser's location API, accurate to a few meters when granted. | |
Account details | name=Jane Doe, email=jane.doe@gmail.com | Your name, email and password, sent in the same request on the registration path. | |
OAuth identity token | id_token=eyJhbGciOiJSUzI1NiIsImtpZCI6... | The Apple or Google ID token proving who you are, sent alongside the coordinates on the login paths. |
- api.adblockninja.com
The vendor's own account and auth backend. Receives the location field on /users/register, /auth/apple and /auth/google, not a filter-list or ad-serving endpoint.
Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.
What it can do
Permissions this extension asks for, as declared in version 1.0.8. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
<all_urls>
Store data in your browser
storage
Sign you in with your Google account
identity
Watch every request your browser makes
webRequest
Watch, block and rewrite every request your browser makes
webRequestBlocking
See which of your requests its blocking rules matched
declarativeNetRequestFeedback
Run its own code inside the pages you visit
scripting
See the address and title of every tab you have open
tabs
See every page you navigate to, as you navigate to it
webNavigation
Store an unlimited amount of data in your browser
unlimitedStorage
Read your physical location
geolocation
Block and redirect the requests your browser makes
declarativeNetRequest
Show you desktop notifications
notifications
Where it sends data
Destinations our analysis observed AdBlock Ninja – Block Ads, Boost Privacy, and Browse Faster contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- api.adblockninja.com
AdBlock Ninja – Block Ads, Boost Privacy, and Browse Faster sends data to api.adblockninja.com. No other extension we have analysed sends data here.