Is Web ad blocker safe?

High risk

Web AdBlocker is high risk. This ad blocker fetches scraping orders from a remote server every time you load a Google search page. The response fully controls whether, what, and where it scrapes Facebook and LinkedIn ad libraries.

webadblockerpluginv3.3.3Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-829
SourceAI SANDBOX

Web ad blocker fetches remote scraping orders on every Google search

This ad blocker fetches scraping orders from a remote server every time you load a Google search page.

The response fully controls whether, what, and where it scrapes Facebook and LinkedIn ad libraries.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open any Google search results page.

This works on google.com and 180+ country-specific Google search domains.

The extension did this

A content script fires immediately and asks the background service worker to fetch scraping orders from a remote server.

No button click, popup, or other interaction with the extension is required.

02EvidenceNETWORK CAPTURE
Captured request
GEThttps://metaextension.ads-collect.com/adscollector/get-meta-query
200 OK, body {"shouldScrap":false,"data":null}. The request fired within the same second the search page finished loading, before any interaction with the page.
Headers
Acceptapplication/json
Content-Typeapplication/json
AuthorizationBearer <redacted>
03EvidenceCODE COMPARE
The code that does this

The remote server's answer is dropped straight into the scraper's config

What it actually does
const prodBaseUrl = 'https://metaextension.ads-collect.com'
const BASE_URL = `${prodBaseUrl}/adscollector`

const API_ENDPOINTS = {
    GET_QUERY: `${BASE_URL}/get-meta-query`,
    AUTHORIZATION_TOKEN: '<redacted, hardcoded, identical for every install>'
}

const getQuery = async () => {
    try {
        return await sendRequest('getQuery', {
            url: API_ENDPOINTS.GET_QUERY,
            method: 'GET',
            headers: {
                "Authorization": `Bearer ${API_ENDPOINTS.AUTHORIZATION_TOKEN}`
            },
            responseType: 'json'
        })
    } catch (err) {
        throw err
    }
}

async function collectAds() {
    try {
        if (isScraping) return;
        isScraping = true;
        const query = await getQuery();
        if (!query.shouldScrap) {
            isScraping = false;
            return;
        }
        await MetaAdsLibrary.initialise(query.data);
    } catch (err) {
        console.log("Error While Collecting Ads:", err);
        isScraping = false;
    }
}
04EvidenceFIELD TABLE
What the remote server controls on every run
FieldValueWhy it matters
Search keyword
"burger delivery offer"Sets the exact term the extension looks up in Facebook's ad library from your browser.
Country / country code
"US" / "GB"Picks which country's ad library your browser is told to scrape.
Ad type & platform
"POLITICAL_AND_ISSUE_ADS", "FACEBOOK"Narrows the scrape to a specific ad category and platform.
Date range
2026-08-01 to 2026-09-01Sets the start and end dates for the ads your browser is told to pull.
Result count
50Caps how many ads the extension retrieves in this pass.
Request / query ID
req_8841f2 / dq_20260908_03Tags the run so the server can match results back to its own job queue.
05EvidenceTHIRD PARTY LIST
Where the traffic goes
  • metaextension.ads-collect.com

    Issues the scraping orders on every Google search and receives the scraped ad data back.

  • facebook.com

    Ad Library GraphQL endpoint queried for ad creative and targeting data on the server's orders.

  • linkedin.com

    Ad Library endpoint queried the same way, under a parallel remote-controlled flow.

06EvidenceARTIFACT
Reproduce it yourself

Replays the same unprompted GET the extension fires on every Google search, and prints whatever scraping orders the remote server currently returns.

RequiresNode.js 18+
check-scrape-orders.js · js
// check-scrape-orders.js
// Replays the request this "ad blocker" extension fires automatically
// on every Google search page load, and prints the server's answer.
// Node.js 18+ (built-in fetch). Omits the extension's own hardcoded
// bearer token; the endpoint answered without it during our test.

const ENDPOINT = "https://metaextension.ads-collect.com/adscollector/get-meta-query";

async function main() {
  const res = await fetch(ENDPOINT, {
    method: "GET",
    headers: {
      "Accept": "application/json",
      "Content-Type": "application/json",
    },
  });

  const body = await res.json().catch(() => null);
  console.log(`HTTP ${res.status}`);
  console.log(JSON.stringify(body, null, 2));

  if (body && body.shouldScrap) {
    console.log("\nServer is CURRENTLY ARMED with live scraping parameters:");
    console.log(JSON.stringify(body.data, null, 2));
  } else {
    console.log("\nServer declined to arm scraping in this check (shouldScrap is false or missing).");
  }
}

main().catch((err) => {
  console.error("Request failed:", err.message);
  process.exit(1);
});
How to run it
  1. 1
    Install Node.js 18 or newer.
  2. 2
    Run `node check-scrape-orders.js`.
  3. 3
    Read the printed shouldScrap value: true means live scraping orders were returned.

What it can do

Permissions this extension asks for, as declared in version 3.3.3. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    *://*/*

  • See the address and title of every tab you have open

    tabs

  • Store data in your browser

    storage

  • Block and redirect the requests your browser makes

    declarativeNetRequest

  • Show you desktop notifications

    notifications

Updated 30 September 2026linepocmmjmnmfepinfkfdbmcndjfafb