Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeAd Block Wonder
Findings · 3
+10 more findings locked
HIGH FINDINGS · 3
  1. 01C2 endpoint rotated from wonder-5_5.php to wonder57.php; all data exfiltration and remote config delivery now uses new versioned URL
  2. 02Server vends google_css_raw blob; extension injects it as CSS into every google.* tab on every navigation via scripting.insertCSS, allowing server to manipulate Google search result page appearance
  3. 03Click-unblocker: server-supplied allowedTrackersDomain list causes entire destination tabs — including search-engine click-throughs — to be exempted from all DNR blocking
+10 more findings locked
OTHER EXTENSIONS

Is Ad Block Wonder safe?

High risk

No summary available.

Wonder Blockv3.8Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+10 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026fpkbnjejghdcncegfglnapabnljcimdc

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact