Is Web ad blocker safe?
Web AdBlocker is high risk. This ad blocker fetches scraping orders from a remote server every time you load a Google search page. The response fully controls whether, what, and where it scrapes Facebook and LinkedIn ad libraries.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Web ad blocker fetches remote scraping orders on every Google search
This ad blocker fetches scraping orders from a remote server every time you load a Google search page.
The response fully controls whether, what, and where it scrapes Facebook and LinkedIn ad libraries.
You open any Google search results page.
This works on google.com and 180+ country-specific Google search domains.
A content script fires immediately and asks the background service worker to fetch scraping orders from a remote server.
No button click, popup, or other interaction with the extension is required.
| Accept | application/json |
| Content-Type | application/json |
| Authorization | Bearer <redacted> |
The remote server's answer is dropped straight into the scraper's config
const prodBaseUrl = 'https://metaextension.ads-collect.com'
const BASE_URL = `${prodBaseUrl}/adscollector`
const API_ENDPOINTS = {
GET_QUERY: `${BASE_URL}/get-meta-query`,
AUTHORIZATION_TOKEN: '<redacted, hardcoded, identical for every install>'
}
const getQuery = async () => {
try {
return await sendRequest('getQuery', {
url: API_ENDPOINTS.GET_QUERY,
method: 'GET',
headers: {
"Authorization": `Bearer ${API_ENDPOINTS.AUTHORIZATION_TOKEN}`
},
responseType: 'json'
})
} catch (err) {
throw err
}
}
async function collectAds() {
try {
if (isScraping) return;
isScraping = true;
const query = await getQuery();
if (!query.shouldScrap) {
isScraping = false;
return;
}
await MetaAdsLibrary.initialise(query.data);
} catch (err) {
console.log("Error While Collecting Ads:", err);
isScraping = false;
}
}| Field | Value | Why it matters | |
|---|---|---|---|
Search keyword | "burger delivery offer" | Sets the exact term the extension looks up in Facebook's ad library from your browser. | |
Country / country code | "US" / "GB" | Picks which country's ad library your browser is told to scrape. | |
Ad type & platform | "POLITICAL_AND_ISSUE_ADS", "FACEBOOK" | Narrows the scrape to a specific ad category and platform. | |
Date range | 2026-08-01 to 2026-09-01 | Sets the start and end dates for the ads your browser is told to pull. | |
Result count | 50 | Caps how many ads the extension retrieves in this pass. | |
Request / query ID | req_8841f2 / dq_20260908_03 | Tags the run so the server can match results back to its own job queue. |
- metaextension.ads-collect.com
Issues the scraping orders on every Google search and receives the scraped ad data back.
- facebook.com
Ad Library GraphQL endpoint queried for ad creative and targeting data on the server's orders.
- linkedin.com
Ad Library endpoint queried the same way, under a parallel remote-controlled flow.
Replays the same unprompted GET the extension fires on every Google search, and prints whatever scraping orders the remote server currently returns.
// check-scrape-orders.js
// Replays the request this "ad blocker" extension fires automatically
// on every Google search page load, and prints the server's answer.
// Node.js 18+ (built-in fetch). Omits the extension's own hardcoded
// bearer token; the endpoint answered without it during our test.
const ENDPOINT = "https://metaextension.ads-collect.com/adscollector/get-meta-query";
async function main() {
const res = await fetch(ENDPOINT, {
method: "GET",
headers: {
"Accept": "application/json",
"Content-Type": "application/json",
},
});
const body = await res.json().catch(() => null);
console.log(`HTTP ${res.status}`);
console.log(JSON.stringify(body, null, 2));
if (body && body.shouldScrap) {
console.log("\nServer is CURRENTLY ARMED with live scraping parameters:");
console.log(JSON.stringify(body.data, null, 2));
} else {
console.log("\nServer declined to arm scraping in this check (shouldScrap is false or missing).");
}
}
main().catch((err) => {
console.error("Request failed:", err.message);
process.exit(1);
});
- 1Install Node.js 18 or newer.
- 2Run `node check-scrape-orders.js`.
- 3Read the printed shouldScrap value: true means live scraping orders were returned.
What it can do
Permissions this extension asks for, as declared in version 3.3.3. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
*://*/*
See the address and title of every tab you have open
tabs
Store data in your browser
storage
Block and redirect the requests your browser makes
declarativeNetRequest
Show you desktop notifications
notifications