Is BlockSite Block Websites & Stay Focused safe?

Medium risk

Block Site is medium risk. BlockSite injects a script into every http(s) page's JS context before page scripts run. It overwrites fetch and XHR.send to capture every response, even with no blocking rule. Captured URLs/bodies are checked against a remote rule list.…

BlockSitev7.1.1Chrome Web Store
45Risk
Who publishes it

BlockSite LP - no other listings under this identity, 1 shared hostname

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
BlockSite
Declared legal entity
BlockSite LP
Registered address
1007 N Orange St, Wilmington, DE 19801-1239, US
Registered contact
BlockSite LP

Shared hosts - 1 hostname

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

blocksite.co
Also called by 3 other listings, including BlockSite

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

BlockSite Reads the Full Response Body of Every Network Request

BlockSite injects a script into every http(s) page's JS context before page scripts run.

It overwrites fetch and XHR.send to capture every response, even with no blocking rule.

Captured URLs/bodies are checked against a remote rule list.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open any website while BlockSite is installed.

The extension did this

BlockSite injects a script into the page's own JS context that overrides fetch and XHR.send to read the full body of every response the page receives.

This runs on every http(s) page, whether or not BlockSite has a blocking rule configured for that specific site.

02EvidenceCODE COMPARE
The code that does this

The XHR interceptor that reads and broadcasts every response body

What it actually does
// Installed by overwriting XMLHttpRequest.prototype.send, once per request instance.
// Runs inside the PAGE's own JavaScript context (injected via a <script> tag),
// not the extension's isolated content-script world.
function patchedSend() {
  this.addEventListener('load', function () {
    let responseBody = null;
    try {
      responseBody = this.responseText; // the full response body, read unconditionally
    } catch (e) {}

    // Broadcast the captured body + request URL as a page-level DOM event
    const captureEvent = new CustomEvent('active-content-block', {
      detail: { way: 'xhr', event: responseBody, url: this.__requestUrl }
    });
    self.dispatchEvent(captureEvent);
  });

  originalSend.apply(this, arguments);
  // A 1-second no-op timeout follows in the shipped build; it has no
  // observable effect on the capture itself.
}
03EvidenceNETWORK CAPTURE
Captured request
POSThttps://category.blocksite.co/sites/blockrate
Observed during dynamic analysis: 200 OK, roughly 235 KB of JSON. The response is stored under chrome.storage.local key 'cDXLl' and, unless it already carries a 'type' field, is decoded via a custom transposition-plus-base64 scheme before use, the on-disk copy is deliberately obscured against casual inspection.
Body
{
  "sid": "a6cf643b7"
}
04EvidenceFIELD TABLE
What the interceptor reads on every page:
FieldValueWhy it matters
Full response body text
(illustrative) {"account":{"email":"jane@example.com","plan":"pro"}}The complete text of every response an XHR or fetch call on the page receives, API responses, account data, or anything else the site loads.
Request and page URL
https://mail.example.com/api/v3/inbox?page=1The exact address of the page you're on and the specific API endpoint being called.
Obfuscated rule list
chrome.storage.local key 'cDXLl' (encoded)A remotely-updatable list of URL and content patterns BlockSite uses to decide what to do with a captured response.
Rule refresh interval
21600000 ms (6 hours)How often BlockSite checks BlockSite's own server for an updated rule list.
05EvidencePLAIN NOTE
What we did and didn't confirm

We confirmed the XHR response-body capture is unconditional — it fires on a page with no matching BlockSite rule — by dispatching a plain request on such a page and observing the capture event with the full response body. The fetch-response capture path only activates once a rule's URL pattern matches the page. The rule source is BlockSite's own backend, and the rule engine we read also handles video-ad-detection ('VAST') rule types, so this mechanism can plausibly power a legitimate content-filtering feature rather than exist solely to collect page data. What we flag is the scope and design: full-body network interception across every website, remotely retargetable by BlockSite at any time, with the on-disk configuration deliberately obscured from casual inspection. We did not trace whether a matched capture is ever transmitted off the device beyond the internal chrome.runtime.sendMessage call to BlockSite's own service worker.

06EvidenceARTIFACT
Reproduce it yourself

Listens for BlockSite's internal capture event and issues a normal same-origin fetch to show the interceptor runs even on a page with no matching BlockSite rule.

RequiresChrome with BlockSite extension installedAny http(s) page loaded
blocksite-response-capture-check.js · js
// blocksite-response-capture-check.js
// Run in the DevTools console of ANY http(s) page while BlockSite is installed,
// including a page with no BlockSite blocking rule for it.

self.addEventListener('active-content-block', (e) => {
  console.log('[BLOCKSITE-INTERCEPT] captured response:', e.detail);
});

// Trigger any request the page would normally make. A same-origin fetch works.
fetch(location.origin + '/', { method: 'GET' }).catch(() => {});
How to run it
  1. 1
    Install BlockSite, open any http(s) page (no rule needed).
  2. 2
    Open DevTools, Console.
  3. 3
    Paste and run this script.
  4. 4
    Reload or trigger a request.
  5. 5
    The response body/URL log, confirming BlockSite read it.
SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

BlockSite Collects All Open Tab URLs on Install

The moment BlockSite finishes installing, it reads every open tab's URL and sends them to statistics.blocksite.co, no prompt.

The request fires from the install handler, no interaction.

Only HTTP/HTTPS URLs, but any open page is captured.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You install BlockSite from the Chrome Web Store.

The extension did this

The extension immediately reads all open tab URLs in your current window and POSTs them to statistics.blocksite.co.

No user interaction is needed beyond installation. The collection happens before you have opened BlockSite's settings or accepted any prompt.

02EvidenceNETWORK CAPTURE
Captured request
POSThttps://statistics.blocksite.co/event/createOnInstallEvent
Observed during dynamic analysis, fired ~2 seconds after install. No Authorization header present.
Headers
Content-Typeapplication/json
Body
{
  "urls": [
    "https://www.google.com/account/about/?hl=en-US",
    "https://www.facebook.com/"
  ],
  "platform": "extension",
  "timestamp": 1780652280218,
  "eventType": "install"
}
03EvidenceFIELD TABLE
What BlockSite sends at install time:
FieldValueWhy it matters
All open tab URLs
https://www.google.com/account/about/?hl=en-USEvery HTTP or HTTPS page you have open in your current window at the moment of installation.
Platform identifier
extensionHardcoded string identifying this as the browser extension client.
Install timestamp
1780652280218Millisecond-precision timestamp of when installation occurred.
Event type
installHardcoded label classifying this as an install-time event.
04EvidenceCODE COMPARE
The code that does this

The install handler that collects and transmits tab URLs

What it actually does
// Fires from chrome.runtime.onInstalled handler
async function sendInstallEvent() {
  // One-shot guard: skip if already sent
  const alreadyFired = await storage.get(STORAGE_KEYS.IS_INSTALL_EVENT_FIRED);
  if (alreadyFired) return;

  try {
    chrome.tabs.query({ currentWindow: true }, (tabs) => {
      // Collect all HTTP/HTTPS tab URLs
      const urls = tabs
        .map(tab => tab.url)
        .filter(url => url.indexOf('http') === 0);

      if (urls.length) {
        fetch(STATISTICS_SERVICE + '/event/createOnInstallEvent', {
          method: 'POST',
          headers: { 'Content-Type': 'application/json' },
          body: JSON.stringify({
            urls,
            platform: 'extension',
            timestamp: Date.now(),
            eventType: 'install'
          })
          // No Authorization header
        });
      }
    });
  } catch (e) {
    logger.error('failed to send install event', e);
  }

  // Mark as sent so it never fires again
  await storage.set(STORAGE_KEYS.IS_INSTALL_EVENT_FIRED, true);
}
05EvidenceTHIRD PARTY LIST
Where the tab URLs are sent:
  • statistics.blocksite.co

    BlockSite's own analytics backend. Receives the install-time tab URL payload with no authentication. Owned and operated by BlockSite (Artium Technologies Ltd.).

Updated 30 September 2026eiimnmioipafcokbfikbljfdeojpcgbh