Chrome Web Store
188Versions
1Code reviewed

No malware found

In code review (v2026.516.1652)

Our reviewer read version 2026.516.1652 — the most recent version we have reviewed — and found no malicious behaviour. The version shown here has not been individually reviewed yet.

What our analysis found

uBlock Origin Lite, used by 21,000,000 people, showed no malicious code in Extension Auditor's review. Its permissions mean it can read and change data on all websites and can inject scripts into pages. It comes from a trusted publisher and was last updated in September 2026.

uBlock Origin Lite is a well-known, open-source (GPL v3) MV3 content blocker by Raymond Hill (gorhill), one of the most trusted names in browser privacy tooling. The source code reviewed in is entirely focused on managing declarativeNetRequest rulesets, per-site filtering modes, and internal extension messaging with strict origin checking (sender.origin!== UBOL_ORIGIN guard at line 405). The web_accessible_resources are stub replacements for ad and tracking SDKs ( returns a random browserId and empty arrays; is a bare IIFE) — this is the canonical anti-fingerprinting technique used by ad blockers, not malicious fingerprinting. The ML model was driven by high JS file count, large total size, and regex hits that all derive from the multilingual filter rule scriptlets bundled for ~50 languages, not from any data-exfiltration logic. The bundled manifest has two additional permissions not listed in the published manifest summary (offscreen and userScripts), which is consistent with the extension having been updated 1 day ago while the CWS-provided listing data lags behind — both permissions are expected and necessary for MV3 content filtering. Third-party risk likelihood score of and Google trusted+featured publisher status directly contradict the ML verdict.

uBlock Origin Lite

uBlock Origin Lite

ID: ddkjiahejlhfcafbddmgiahcphecmpfh

Supported Languages

🇸🇦Arabic
🇧🇩Bengali
🇧🇷Brazilian Portuguese
🇬🇧British English
🇧🇬Bulgarian
🇪🇸Catalan
🇨🇳Chinese (Simplified)
🇹🇼Chinese (Traditional)
🇭🇷Croatian
🇨🇿Czech
🇩🇰Danish
🇳🇱Dutch
🇺🇸English
🇪🇪Estonian
🇵🇭Filipino
🇫🇮Finnish
🇫🇷French
🇩🇪German
🇬🇷Greek
🇮🇳Gujarati
🇮🇱Hebrew
🇮🇳Hindi
🇭🇺Hungarian
🇮🇩Indonesian
🇮🇹Italian
🇯🇵Japanese
🇮🇳Kannada
🇰🇷Korean
🇱🇻Latvian
🇱🇹Lithuanian
🇲🇾Malay
🇮🇳Malayalam
🇮🇳Marathi
🇳🇴Norwegian
🇮🇷Persian
🇵🇱Polish
🇵🇹Portuguese
🇷🇴Romanian
🇷🇺Russian
🇷🇸Serbian
🇸🇰Slovak
🇸🇮Slovenian
🇪🇸Spanish
🇰🇪Swahili
🇸🇪Swedish
🇮🇳Tamil
🇮🇳Telugu
🇹🇭Thai
🇹🇷Turkish
🇺🇦Ukrainian
🇻🇳Vietnamese

Extension Info & Metadata

Status
Active
Version
2026.930.1227
Size
9.20 MB
Rating
4.0/5
Reviews
3,612
Users
21,000,000
Type
Extension
Updated
Sep 30, 2026
Category
Make_chrome_yours Privacy
Price
Free
Featured
Yes
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes
This publisherTrack record
12extensions
7 no longer listed
Scanned by Extension Auditor — Low RiskDevelopers: embed this badge to link to this report.

Publisher Contextual Analysis

Trusted
Author
Raymond Hill (gorhill)View Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Website
Visit
Extensions
12
Active
5
Obsolete
7
Listed
9
Unlisted
3
Users
47,589,972

Screenshots & videos

Screenshot 1
Screenshot 2
Screenshot 3
Screenshot 4
Screenshot 5

Install growth

Item
Type
Severity
Description
declarativeNetRequest
Permission
Critical
This permission allows the extension to define rules to block, redirect, or modify network requests. Rated Critical because it can control all network traffic, potentially blocking security updates or redirecting to malicious sites.
scripting
Permission
Critical
This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to.
userScripts
Permission
Critical
This permission allows registration of arbitrary user scripts that run in a page's main world. Rated Critical because the scripts execute with full access to page JavaScript, can be updated at runtime from remote code, and bypass the isolated world that normally contains content scripts.
<all_urls>
Host
Critical
Broad host access — the extension can read/modify content on every website.
offscreen
Permission
High
This permission creates hidden browser documents with full DOM access. Rated High because it can run background operations invisibly, potentially executing malicious code without user awareness.
Broad Host Permissions
Risk Factor
High
This extension has broad host permissions allowing it to access many or all websites.
Broad Content Script Access
Risk Factor
High
This extension can inject scripts into any website.
activeTab
Permission
Medium
This permission grants temporary access to the current tab. Rated Medium because it can access current page content when invoked, though limited to user-initiated actions.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
unlimitedStorage
Permission
Medium
This permission removes storage quota restrictions. Rated Medium because it can store large amounts of user data without limits, potentially impacting browser performance and storing extensive tracking data.
alarms
Permission
Low
This permission schedules periodic tasks. Rated Low because it can only trigger events at specified times without access to sensitive data.

Gain full insight into all external connections.

Upgrade for full visibility.

About this extension

An efficient content blocker. Blocks ads, trackers, miners, and more immediately upon installation.

Read the publisher’s full description

uBO Lite (uBOL) is an efficient MV3-based content blocker. The default ruleset corresponds to uBlock Origin's default filterset: - uBlock Origin's built-in filter lists - EasyList - EasyPrivacy - Peter Lowe’s Ad and tracking server list You can enable more rulesets by visiting the options page -- click the _Cogs_ icon in the popup panel. uBOL is entirely declarative, meaning there is no need for a permanent uBOL process for the filtering to occur, and CSS/JS injection-based content filtering is performed reliably by the browser itself rather than by the extension. This means that uBOL itself does not consume CPU/memory resources while content blocking is ongoing -- uBOL's service worker process is required _only_ when you interact with the popup panel or the option pages.

User reviews

Extension files

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.

No network indicators were extracted from this version.

Showing 1 to 10 of 190 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files detected

No comparable text files found between these versions.

Gain full insight into all external connections.

Upgrade for full visibility.

More from Raymond Hill (gorhill)

Popular in make_chrome_yours/privacy