StopAds

ID: ifgaaponbijdnndjdbcmbeaipgeadolh

Could be malicious

Extension Info & Metadata

Status
Removed
Version
2.14.88
Size
0.38 MB
Rating
3.3/5
Reviews
3
Users
26,869
Type
Extension
Updated
Mar 9, 2021
Category
7_productivity
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
No

Publisher Contextual Analysis

Author
Ryder ErnserView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Total Extensions
1
Active
0
Obsolete
1
Listed
1
Unlisted
0
Total Users
26,869

Block all kinds of ads. Permanently

Stopads protects you from ads while surfing the web. 🛑 STOPADS FEATURES 🛑 ✰ Ad blocking Stopads blocks all kinds of ads - banners, popups, video ads, etc. ✰ Easy setup It’s ready after install. No need for adding filters manually, disabling “acceptable ads”. ✰ Whitelist Use the extension button in the toolbar to add a site to the whitelist.

Item
Type
Severity
Description
<all_urls>
Permission
Critical
This permission grants access to all websites without restriction. Rated High because it can access any web content, monitor all web activity, and potentially steal sensitive data across all sites.
webRequest
Permission
Critical
This permission enables the extension to monitor and analyze all web requests made by the browser. Rated Critical because it can observe all network traffic including sensitive data, track browsing behavior, and gather authentication tokens.
webRequestBlocking
Permission
Critical
This permission allows the extension to intercept, modify, or block any web request in real-time before it reaches its destination. Rated Critical because it can modify sensitive data (like passwords, credit cards) before encryption, redirect traffic to malicious sites, or block security updates.
Dangerous Permission Combination
Risk Factor
Critical
This extension can intercept, modify, and block web requests in real-time.
webNavigation
Permission
High
This permission enables monitoring of all browser navigation events and transitions. Rated High because it can track every page visit, navigation method, and browsing pattern, potentially exposing sensitive browsing behavior and user activities.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 10% increase: Early script execution enables pre-emptive content manipulation• 15% increase: Older manifest version lacks modern security controls• 10% increase: About:blank access enables potential sandbox escape vectors
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
unlimitedStorage
Permission
Medium
This permission removes storage quota restrictions. Rated Medium because it can store large amounts of user data without limits, potentially impacting browser performance and storing extensive tracking data.
Early Content Script Execution
Risk Factor
Medium
This extension runs content scripts at document_start.
About:blank Access
Risk Factor
Medium
This extension can run content scripts in about:blank pages.
Older Manifest Version
Risk Factor
Medium
This extension uses Manifest Version 2

An ad-blocking extension that claims to protect users from tracking explicitly allowlists Google Analytics and Google Tag Manager in its Content Security Policy. This is contradictory to the extension's stated purpose and, given that popup.js was not available for analysis, it cannot be confirmed that these tracking services are not loaded in the popup. No CWS privacy disclosure covers behavioral or analytics data collection, making this undisclosed third-party tracking if the scripts are loaded.

manifest.json (Line 24)
{  "content_security_policy": [    "script-src 'self' https://www.google-analytics.com https://*.googleapis.com https://www.googletagmanager.com",    "object-src 'self'"  ]}

The popup loads a stylesheet over plain HTTP from allfont.ru, a third-party Russian font CDN. Any network attacker on the path (ISP, Wi-Fi AP) can intercept this request and inject CSS or content into the extension popup. For a security extension handling sensitive UI state, loading third-party resources over HTTP is an unnecessary attack surface, and allfont.ru has no relationship to the extension's ad-blocking function.

popup.html (Line 2)
< link href="http://allfont.ru/allfont.css?fonts=furore" rel="stylesheet" type="text/css">

By severity

Critical0
High0
Medium2
Low0

Versions scanned

Showing 1 of 3 scanned versions with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
2.14.882

Files with findings

2 distinct paths — top paths by unique finding count:

  • manifest.json1
  • popup.html1
S.No.
Category
Severity
File
Summary
Found in Version
1Other
medium
popup.html (line 2)The popup loads a stylesheet over plain HTTP from allfont.ru, a third-party Russian font CDN. Any network attacker on the path (ISP, Wi-Fi AP) can intercept this request and inject CSS or content into the extension po…
2Tracking
medium
manifest.json (line 24)An ad-blocking extension that claims to protect users from tracking explicitly allowlists Google Analytics and Google Tag Manager in its Content Security Policy. This is contradictory to the extension's stated purpose…
URLs
65
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

developer.mozilla.org/docs/Mozilla/Add-ons/WebExtensions/API/runtime/onMessagehttps://developer.mozilla.org/docs/Mozilla/Add-ons/WebExtensions/API/runtime/onMessage
npms.io/searchhttps://npms.io/search?q=ponyfill.
*/*http://*/*
*/*https://*/*
chrome.google.com/webstore/https://chrome.google.com/webstore/
adblockplus.org/getSubscriptionhttps://adblockplus.org/getSubscription?version=%VERSION%&url=%SUBSCRIPTION%&downloadURL=%URL%&error=%ERROR%&channelStatus=%CHANNELSTATUS%&responseStatus=%RESPONSESTATUS%
rules.easyadblocker.com/exceptionrules.txthttps://rules.easyadblocker.com/exceptionrules.txt
rules.easyadblocker.com/exceptionrules-privacy-friendly.txthttps://rules.easyadblocker.com/exceptionrules-privacy-friendly.txt
rules.easyadblocker.com/antiadblockfilters.txthttps://rules.easyadblocker.com/antiadblockfilters.txt
adblockplus.org/redirecthttps://adblockplus.org/redirect?link=%LINK%&lang=%LANG%
Showing 1 to 10 of 70 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Version
Size
Is Malicious
Findings
Permhash
2.14.88
Latest
0.39 MB
Malicious
2
2.14.87
0.33 MB
Malicious
—
2.14.89
0.38 MB
Malicious
—
Showing 1 to 3 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.