Luminous: JavaScript events blocker

Luminous: JavaScript events blocker

ID: baacpbikplogpeecclpnajnlghmcldkb

Supported Languages

🇧🇷Brazilian Portuguese
🇪🇸Spanish
🇺🇸US English

Extension Info & Metadata

Status
Active
Version
0.0.28
Size
0.37 MB
Rating
4.9/5
Reviews
19
Users
918
Type
Extension
Updated
Sep 14, 2019
Category
Developer tools
Price
Free
Featured
No
Visibility
Unlisted
Mature
No
By Google
No
Trusted
Yes

Publisher Contextual Analysis

Trusted
Author
gbaptistaView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Total Extensions
1
Active
1
Obsolete
0
Listed
0
Unlisted
1
Total Users
918
Screenshot 1
Screenshot 2
Screenshot 3
Screenshot 4
Screenshot 5

An experimental extension to identify, analyze and block code execution and event collection through JavaScript in your browser.

We have amazing projects like Lightbeam, NoScript, ScriptSafe, uBlock Origin, HTTPS Everywhere and many others. All have the proposal to identify and/ or prevent the execution of questionable codes and requests. These tools are vital, but we inevitably need to make concessions to access many websites as we have a massive use of JavaScript on the web. When you access for example the Google Translate website, with a combo of 3 extensions (HTTPS Everywhere, uBlock Origin and ScriptSafe) and Luminous, we have the following result after a few moments: - 6 requests influenced by HTTPS Everywhere - 75 requests blocked by uBlock Origin - 4 items blocked by ScriptSafe - 7,6 thousand JavaScript executions detected by Luminous It’s about this number (7,6 thousand) that we are lost and with hands tied, it’s there that we do not know what happens and we still do not have the freedom to decide what can or can’t be executed. This is the main purpose of the project, filling this gap and being able to see and control what happens. As a side effect we end up also having an interesting tool that helps in JavaScript code developing process by giving us visibility about what is happening.

Item
Type
Severity
Description
webRequest
Permission
Critical
This permission enables the extension to monitor and analyze all web requests made by the browser. Rated Critical because it can observe all network traffic including sensitive data, track browsing behavior, and gather authentication tokens.
webRequestBlocking
Permission
Critical
This permission allows the extension to intercept, modify, or block any web request in real-time before it reaches its destination. Rated Critical because it can modify sensitive data (like passwords, credit cards) before encryption, redirect traffic to malicious sites, or block security updates.
<all_urls>
Permission
Critical
This permission grants access to all websites without restriction. Rated High because it can access any web content, monitor all web activity, and potentially steal sensitive data across all sites.
Dangerous Permission Combination
Risk Factor
Critical
This extension can intercept, modify, and block web requests in real-time.
webNavigation
Permission
High
This permission enables monitoring of all browser navigation events and transitions. Rated High because it can track every page visit, navigation method, and browsing pattern, potentially exposing sensitive browsing behavior and user activities.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 10% increase: Early script execution enables pre-emptive content manipulation• 15% increase: Older manifest version lacks modern security controls
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
unlimitedStorage
Permission
Medium
This permission removes storage quota restrictions. Rated Medium because it can store large amounts of user data without limits, potentially impacting browser performance and storing extensive tracking data.
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
Early Content Script Execution
Risk Factor
Medium
This extension runs content scripts at document_start.
Older Manifest Version
Risk Factor
Medium
This extension uses Manifest Version 2
URLs
41
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

github.com/gbaptista/luminous/releases/tag/0.0.28https://github.com/gbaptista/luminous/releases/tag/0.0.28
www.iconfinder.com/icons/1459441/anatomy_eye_halloween_holidays_iconhttps://www.iconfinder.com/icons/1459441/anatomy_eye_halloween_holidays_icon
www.iconfinder.com/Reviconhttps://www.iconfinder.com/Revicon
dexie.org/docs/Tutorial/Designhttp://dexie.org/docs/Tutorial/Design#database-versioning
developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Typehttps://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Type
developer.mozilla.org/en-US/docs/Web/HTTP/Basics_of_HTTP/MIME_typeshttps://developer.mozilla.org/en-US/docs/Web/HTTP/Basics_of_HTTP/MIME_types
github.com/gbaptista/luminous/issues/107https://github.com/gbaptista/luminous/issues/107
github.com/EFForg/privacybadger/pull/1954https://github.com/EFForg/privacybadger/pull/1954
github.com/gbaptista/luminous/blob/0.0.28/js/content/interceptor.jshttps://github.com/gbaptista/luminous/blob/0.0.28/js/content/interceptor.js
github.com/gbaptista/luminous/blob/0.0.28/js/content/interceptors/https://github.com/gbaptista/luminous/blob/0.0.28/js/content/interceptors/
Showing 1 to 10 of 50 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Version
Size
Is Malicious
Findings
Permhash
0.0.28
Latest
0.37 MB
Benign
Showing 1 to 1 of 10 rows
Rows per page:

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.