Is SBlock - Super Ad Blocker safe?
SBlock is medium risk. When you navigate to supported video and social sites, SBlock replaces the page's network functions, letting it read or change fetch and XHR traffic on YouTube and Facebook, including DOM-related page content, automatically on navigation.…
Who publishes itSBlock GmbH - 1 other listing from the same operator, none carrying a finding
SBlock GmbH - 1 other listing from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
1 other listing published from this account, 17 users between them, none of them carrying a finding.
Shared hosts - 16 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
SBlock intercepts page network traffic on YouTube and Facebook.
When you navigate to supported video and social sites, SBlock replaces the page's network functions, letting it read or change fetch and XHR traffic on YouTube and Facebook, including DOM-related page content, automatically on navigation.
The user navigates to a supported site.
The extension replaces page network functions so fetch and XHR traffic on YouTube and Facebook passes through extension code.
| Field | Value | Why it matters | |
|---|---|---|---|
Page DOM content | YouTube page content (illustrative) | Shows the page content available while the extension's network hooks run on supported sites. |
Social-site ad content is posted to addon.sblock.pro
SBlock ships site scripts for Reddit, Twitter/X, TikTok, Pinterest, Facebook, YouTube extracting ad entries, forwarded via the extension broker.
DA confirmed Reddit: two POSTs carried sponsored-post HTML logged out; others sat behind login.
You browse a supported social or video site with SBlock enabled.
The matching site script extracts ad entries and sends an ad object to addon.sblock.pro through the extension background queue.
| Field | Value | Why it matters | |
|---|---|---|---|
Reddit ad HTML | <shreddit-ad-post id="t3_1abc234" author="u_promoted_brand">Sponsored post markup</shreddit-ad-post> | Shows which sponsored Reddit post appeared and the surrounding ad markup from the page. | |
Ad identifiers | promoted-1699-7f4a21 | Lets the ad record be tied back to a specific ad entry on the supported site. | |
Request and browser context | {"platform":"reddit","lang":"en-GB","site":"reddit"} | Adds browser, language, site, or request metadata alongside the ad content. |
Site scripts send ad objects through the broker to the same queue
var V = ({config: n, httpClient: t}) => {
let r = [], i = 0, c = "", s = !1, d = !0;
async function o(S) {
let a = { ...S, agent: q(c, i++) };
delete a.retryCount;
let {status: f, data: p} = await t.post(n.URLS.DATA_COLLECT, { body: a });
if (f !== 200) throw new Error(`Failed to fetch With status: ${f}`);
p.length < 30 && (c = p);
}
async function l() {
if (!s) {
for (s = !0; r.length > 0; ) try {
await o(r[0]), r.shift();
} catch (S) {
r?.[0]?.retryCount < 5 ? r[0].retryCount++ : r.shift(), console.log(S), await J(5);
}
s = !1;
}
}
return {
async enqueue(S) {
return d && (r.push({ retryCount: 1 }), d = !1), r.push({ ...S, retryCount: 1 }), s || await l(), r;
}
};
};- addon.sblock.pro
Receives ad objects collected by supported-site scripts.
- x.com
The Twitter/X script fetches /about-ads?aid=... pages to add ad-transparency text before forwarding the ad object.
Site visit telemetry is sent to Google Analytics and Datadog
On startup, and on a supported site's extension_site_open event, SBlock sends telemetry to Google Analytics and Datadog.
DA captured 24 POSTs to each; the GA body held a persistent UUID client_id, site facebook, version 1.7.16, country UK.
You install or use SBlock on a supported site.
The extension sends telemetry events containing a persistent client ID, site name, country, and extension version to Google Analytics and Datadog.
| Field | Value | Why it matters | |
|---|---|---|---|
Persistent client ID | 1345a6c5-2aae-4640-bb23-14cb3934a9bc | Lets telemetry events from the same browser profile be linked over time. | |
Site opened | Records which supported site generated the event during your browsing session. | ||
Extension version | 1.7.16 | Shows which SBlock version was installed when the event was sent. | |
Country | United Kingdom | Adds coarse location context to the telemetry event. |
{
"client_id": "1345a6c5-2aae-4640-bb23-14cb3934a9bc",
"events": [
{
"name": "extension_site_open",
"params": {
"site": "facebook",
"extension_version": "1.7.16",
"country": "United Kingdom"
}
}
]
}| DD-API-KEY | <redacted> |
Background telemetry services build the observed requests
var at = ({config: n, httpClient: t, clientId: e}) => ({
send({name: r, ...i}) {
return t.post(n.URLS.GOOGLE_API, {
body: {
client_id: e,
events: [ {
name: r,
params: i
} ]
},
params: {
measurement_id: n.GOOGLE_MEASUREMENT_ID,
api_secret: "<redacted>"
}
}).catch(c => {});
}
});
var lt = ({config: n, httpClient: t}) => ({
async send({name: e, ...r}) {
return t.post(n.URLS.METRICS_API, {
body: {
series: [ {
metric: e,
type: 1,
points: [ {
timestamp: X(),
value: 1
} ],
resources: Object.entries(r).map(([i, c]) => ({
type: i,
name: c
}))
} ]
},
headers: {
"DD-API-KEY": "<redacted>"
}
}).catch(i => {});
}
});- www.google-analytics.com
Receives Measurement Protocol events with client_id and event params.
- api.datadoghq.com
Receives metric series events with site, extension version, and country resources.
+4 more findings not shown