Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeAllstate Ad Blocker
Findings · 3
+2 more findings locked
LOW FINDINGS · 3
  1. 01Dormant code path: when build flag s.enableRealtimeSiteReputation === 'true', getSiteReputation submits the visited URI to Allstate's AppSync GraphQL endpoint as the `uri` argument of the getSiteReputation query -- meaning every navigated URL would be POSTed to the vendor backend.
  2. 02Background script intercepts and blocks every cross-origin subresource request via webRequest.onBeforeRequest({urls:['<all_urls>']},['blocking']); decisions made locally by bundled WASM filter engine.
  3. 03On every tab activation/update/navigation, background.js calls sudoSrClient.getSiteReputation(host) to decide whether to mark the page as malicious; in this build, that resolves to a LOCAL check against a malware/phishing ruleset downloaded from Allstate's S3 bucket -- no per-page network call.
+2 more findings locked
OTHER EXTENSIONS

Is Allstate Ad Blocker safe?

Low risk

No summary available.

Allstate Insurance Companyv1.1.2Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+2 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.aip.anonyome-ad-blocker.web-ext

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact