Is AdBlocker Professional safe?

High risk

AdBlocker Professional is high risk. On install, Adblocker Professional contacts the developer's server and gets a permanent unique identifier tied to your install. It's stored locally and sent in every check-in, letting the developer track you over time. Undisclosed anywhere.…

Pro AdBlockerv2.0.2.3Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Unique tracking ID assigned on install, sent to developer server

On install, Adblocker Professional contacts the developer's server and gets a permanent unique identifier tied to your install.

It's stored locally and sent in every check-in, letting the developer track you over time.

Undisclosed anywhere.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You install the extension for the first time.

The extension did this

The extension immediately contacts the developer's server, receives a permanent unique identifier, and stores it on your device.

The ID is also embedded in the extension's uninstall notification URL so the developer is notified when you remove it.

02EvidenceNETWORK CAPTURE
Captured request
GEThttps://adblockerprofessional.com/install/?version=2.0.2.3
JSON object containing uniqueUserId field, a stable, server-assigned identifier for this installation.
Headers
credentialsinclude
03EvidenceSTORAGE DUMP
What's stored on your device

A base64-encoded unique installation identifier assigned by the developer's server on first install; sent in every later periodic beacon.

Locationchrome.storage.local key 'userId'
Contents
ai9WZkg2SXJUU20veDY0QTU5UmhKeUhYM0p2UU1NR0I3bmlobFBnNGtCYTBuOEFLTEVtd2wwSXF1ckluLzF3MmFDeDAvTFVj
04EvidenceCODE COMPARE
The code that does this

Install handler assigns and stores the tracking ID

What it actually does
chrome.runtime.onInstalled.addListener(async (event) => {
  if (event.reason === chrome.runtime.OnInstalledReason.INSTALL) {
    let userId = 'default';
    try {
      const response = await fetch(
        'https://adblockerprofessional.com/install/?version=' +
          encodeURIComponent(chrome.runtime.getManifest().version),
        { credentials: 'include' }
      );
      const data = await response.json();
      userId = data.uniqueUserId;  // server-assigned tracking ID
    } finally {
      await chrome.storage.local.set({ userId });  // persisted locally
      chrome.runtime.setUninstallURL(
        'https://adblockerprofessional.com/un/?uniqueUserId=' + userId  // notifies on uninstall
      );
    }
  }
});
05EvidenceTHIRD PARTY LIST
Where the install event is reported
  • adblockerprofessional.com

    Developer's own server. Receives the install event and issues the uniqueUserId. Also receives the uninstall notification and all subsequent periodic beacons.

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Persistent tracking ID transmitted to developer server every hour

Adblocker Professional sends your permanent installation ID to the developer's server about once an hour.

The ID never changes, letting the developer build a long-term activity record tied to your device, with no notification.

01EvidenceCAUSE EFFECT
What actually happens
You did this

The extension's internal alarm fires every 60 minutes.

The extension did this

The extension reads your stored unique identifier and sends it to the developer's server along with the extension version.

The same identifier is reused each time, making every beacon linkable to the same installation.

02EvidenceNETWORK CAPTURE
Captured request
GEThttps://adblockerprofessional.com/maj/net_data/?uniqueUserId=ai9WZkg2SXJUU20veDY0QTU5UmhKeUhYM0p2UU1NR0I3bmlobFBnNGtCYTBuOEFLTEVtd2wwSXF1ckluLzF3MmFDeDAvTFVj&version=2.0.2.3
JSON object with network filter configuration data (id, url, v fields). The same uniqueUserId token appeared in 4 consecutive requests during dynamic analysis.
Headers
credentialsinclude
03EvidenceTEMPORAL PATTERN
When this fires
Every 1 day

Beacon fires at most once every 24 hours per the updateNetDataLastRunDate cooldown. With the alarm set to every 60 minutes, the beacon goes out on the first alarm tick after the 24-hour window expires.

04EvidenceCODE COMPARE
The code that does this

Periodic beacon function transmits the stored tracking ID

What it actually does
const sendNetDataBeacon = async () => {
  let { userId, updateNetDataLastRunDate: lastRun } =
    await chrome.storage.local.get(['userId', 'updateNetDataLastRunDate']);
  if (!lastRun) lastRun = 0;
  // 24-hour cooldown
  if (lastRun && Date.now() - lastRun < 24 * 3600 * 1000) return;
  try {
    const result = await fetch(
      'https://adblockerprofessional.com/maj/net_data/?' +
        'uniqueUserId=' + userId +
        '&version=' + encodeURIComponent(chrome.runtime.getManifest().version),
      { credentials: 'include' }
    );
    // ... processes network filter config from response ...
  } finally {
    await chrome.storage.local.set({ updateNetDataLastRunDate: Date.now() });
  }
};
05EvidenceFIELD TABLE
Data transmitted in each periodic beacon
FieldValueWhy it matters
Unique installation ID
ai9WZkg2SXJUU20veDY0QTU5UmhKeUhYM0p2UU1NR0I3bmlobFBnNGtCYTBuOEFLTEVtd2wwSXF1ckluLzF3MmFDeDAvTFVjStable ID assigned by the developer's server on first install, reused in every request to link all beacons to the same device.
Extension version
2.0.2.3The currently installed version number. Lets the developer know which release is active on each tracked installation.
06EvidenceTHIRD PARTY LIST
Destination for periodic tracking beacons
  • adblockerprofessional.com

    Developer's own server. Receives uniqueUserId and version each periodic check-in (at most once per 24h), plus the install ping and uninstall notice.

What it can do

Permissions this extension asks for, as declared in version 2.0.2.3. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    <all_urls>

  • Block and redirect the requests your browser makes

    declarativeNetRequest

  • Run its own code inside the pages you visit

    scripting

  • Store data in your browser

    storage

  • Store an unlimited amount of data in your browser

    unlimitedStorage

  • Schedule its own background tasks

    alarms

Updated 30 September 2026kgknjmfebhekokplfpmodjopebmfdjac