Is SBlock - Super Ad Blocker safe?

Medium risk

SBlock is medium risk. When you navigate to supported video and social sites, SBlock replaces the page's network functions, letting it read or change fetch and XHR traffic on YouTube and Facebook, including DOM-related page content, automatically on navigation.…

Sblockv1.7.20Chrome Web Store
45Risk
Who publishes it

SBlock GmbH - 1 other listing from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Sblock
Declared legal entity
SBlock GmbH
Registered address
Badenerstrasse 48, Zürich 8004, CH
Registered contact
SBlock - Super Ad Blocker

Same store account

1 other listing published from this account, 17 users between them, none of them carrying a finding.

Shared hosts - 16 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

media-reisen.de
Also called by 2 other listings, including aBlock - Ads Blocker
media.amazon.map.fastly.net
Also called by 2 other listings, including aBlock - Ads Blocker
sport.tvp.pl
Also called by 3 other listings, including aBlock - Ads Blocker
analyzer.fc2.com
Also called by 4 other listings
ish.tumedia.no
Also called by 4 other listings, including Ad Block Wonder
rranking3.ziyu.net
Also called by 4 other listings
s1.aspservice.jp
Also called by 4 other listings, including Ad Block Wonder
ssl-wolterskluwer.met.vgwort.de
Also called by 4 other listings, including aBlock - Ads Blocker
t.myvisualiq.net
Also called by 4 other listings, including Ad Block Wonder
ziyu.net
Also called by 4 other listings, including Ad Block Wonder
220forum.ru
Also called by 5 other listings, including Adblock Fortress, Eclipse Ad Blocker, AdLock
playvideolink.com
Also called by 5 other listings, including Adblock Fortress, Eclipse Ad Blocker, AdLock
static.videonow.ru
Also called by 5 other listings, including Adblock Fortress, Eclipse Ad Blocker, AdLock
videochart.net
Also called by 5 other listings, including Adblock Fortress, Eclipse Ad Blocker, AdLock
ads.postimees.ee
Also called by 6 other listings, including Ad Blocker Pro - block ads ad blocker
html-load.com
Also called by 6 other listings, including Ad Blocker Pro - block ads ad blocker

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-506
SourceAI SANDBOX

SBlock intercepts page network traffic on YouTube and Facebook.

When you navigate to supported video and social sites, SBlock replaces the page's network functions, letting it read or change fetch and XHR traffic on YouTube and Facebook, including DOM-related page content, automatically on navigation.

01EvidenceCAUSE EFFECT
What actually happens
You did this

The user navigates to a supported site.

The extension did this

The extension replaces page network functions so fetch and XHR traffic on YouTube and Facebook passes through extension code.

02EvidenceFIELD TABLE
Fields available to the hook
FieldValueWhy it matters
Page DOM content
YouTube page content (illustrative)Shows the page content available while the extension's network hooks run on supported sites.
SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Social-site ad content is posted to addon.sblock.pro

SBlock ships site scripts for Reddit, Twitter/X, TikTok, Pinterest, Facebook, YouTube extracting ad entries, forwarded via the extension broker.

DA confirmed Reddit: two POSTs carried sponsored-post HTML logged out; others sat behind login.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You browse a supported social or video site with SBlock enabled.

The extension did this

The matching site script extracts ad entries and sends an ad object to addon.sblock.pro through the extension background queue.

02EvidenceFIELD TABLE
Data shapes extracted by site scripts
FieldValueWhy it matters
Reddit ad HTML
<shreddit-ad-post id="t3_1abc234" author="u_promoted_brand">Sponsored post markup</shreddit-ad-post>Shows which sponsored Reddit post appeared and the surrounding ad markup from the page.
Ad identifiers
promoted-1699-7f4a21Lets the ad record be tied back to a specific ad entry on the supported site.
Request and browser context
{"platform":"reddit","lang":"en-GB","site":"reddit"}Adds browser, language, site, or request metadata alongside the ad content.
03EvidenceNETWORK CAPTURE
Captured request
POSThttps://addon.sblock.pro/api/v1/external/data
Dynamic analysis observed two Reddit POST requests. The claim evidence records a 2,000-byte Reddit shreddit-ad-post HTML body and a 16,147-byte Reddit ad HTML body.
04EvidenceCODE COMPARE
The code that does this

Site scripts send ad objects through the broker to the same queue

What it actually does
Readable background queue posts all ad objects to DATA_COLLECTbackground.js
var V = ({config: n, httpClient: t}) => {
  let r = [], i = 0, c = "", s = !1, d = !0;
  async function o(S) {
    let a = { ...S, agent: q(c, i++) };
    delete a.retryCount;
    let {status: f, data: p} = await t.post(n.URLS.DATA_COLLECT, { body: a });
    if (f !== 200) throw new Error(`Failed to fetch With status: ${f}`);
    p.length < 30 && (c = p);
  }
  async function l() {
    if (!s) {
      for (s = !0; r.length > 0; ) try {
        await o(r[0]), r.shift();
      } catch (S) {
        r?.[0]?.retryCount < 5 ? r[0].retryCount++ : r.shift(), console.log(S), await J(5);
      }
      s = !1;
    }
  }
  return {
    async enqueue(S) {
      return d && (r.push({ retryCount: 1 }), d = !1), r.push({ ...S, retryCount: 1 }), s || await l(), r;
    }
  };
};
05EvidenceTHIRD PARTY LIST
External destination
  • addon.sblock.pro

    Receives ad objects collected by supported-site scripts.

  • x.com

    The Twitter/X script fetches /about-ads?aid=... pages to add ad-transparency text before forwarding the ad object.

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Site visit telemetry is sent to Google Analytics and Datadog

On startup, and on a supported site's extension_site_open event, SBlock sends telemetry to Google Analytics and Datadog.

DA captured 24 POSTs to each; the GA body held a persistent UUID client_id, site facebook, version 1.7.16, country UK.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You install or use SBlock on a supported site.

The extension did this

The extension sends telemetry events containing a persistent client ID, site name, country, and extension version to Google Analytics and Datadog.

02EvidenceFIELD TABLE
Fields in observed telemetry
FieldValueWhy it matters
Persistent client ID
1345a6c5-2aae-4640-bb23-14cb3934a9bcLets telemetry events from the same browser profile be linked over time.
Site opened
facebookRecords which supported site generated the event during your browsing session.
Extension version
1.7.16Shows which SBlock version was installed when the event was sent.
Country
United KingdomAdds coarse location context to the telemetry event.
03EvidenceNETWORK CAPTURE
Captured request
POSThttps://www.google-analytics.com/mp/collect?measurement_id=G-MJSF1GSELS&api_secret=<redacted>
Dynamic analysis captured 24 POSTs to Google Analytics with this event shape.
Body
{
  "client_id": "1345a6c5-2aae-4640-bb23-14cb3934a9bc",
  "events": [
    {
      "name": "extension_site_open",
      "params": {
        "site": "facebook",
        "extension_version": "1.7.16",
        "country": "United Kingdom"
      }
    }
  ]
}
04EvidenceNETWORK CAPTURE
Captured request
POSThttps://api.datadoghq.com/api/v2/series
Dynamic analysis captured 24 POSTs to Datadog with extension_site_open metrics and resources for site, extension version, and country.
Headers
DD-API-KEY<redacted>
05EvidenceCODE COMPARE
The code that does this

Background telemetry services build the observed requests

What it actually does
var at = ({config: n, httpClient: t, clientId: e}) => ({
  send({name: r, ...i}) {
    return t.post(n.URLS.GOOGLE_API, {
      body: {
        client_id: e,
        events: [ {
          name: r,
          params: i
        } ]
      },
      params: {
        measurement_id: n.GOOGLE_MEASUREMENT_ID,
        api_secret: "<redacted>"
      }
    }).catch(c => {});
  }
});

var lt = ({config: n, httpClient: t}) => ({
  async send({name: e, ...r}) {
    return t.post(n.URLS.METRICS_API, {
      body: {
        series: [ {
          metric: e,
          type: 1,
          points: [ {
            timestamp: X(),
            value: 1
          } ],
          resources: Object.entries(r).map(([i, c]) => ({
            type: i,
            name: c
          }))
        } ]
      },
      headers: {
        "DD-API-KEY": "<redacted>"
      }
    }).catch(i => {});
  }
});
06EvidenceTHIRD PARTY LIST
Telemetry destinations
  • www.google-analytics.com

    Receives Measurement Protocol events with client_id and event params.

  • api.datadoghq.com

    Receives metric series events with site, extension version, and country resources.

+4 more findings not shown

Updated 30 September 2026cmdgdghfledlbkbciggfjblphiafkcgg