Security Ops v10.1.0
⎇ Source
Browser extension · Manifest V3 · Chrome / Edge / Firefox

Privacy-first browser hardening. One source tree, three browsers, zero telemetry.

Security Ops blocks ads, trackers and malware at the network layer with declarativeNetRequest, darkens every site with your accent color, strips YouTube ads before the player sees them, rewrites tracking parameters, upgrades HTTP to HTTPS, routes traffic through a SOCKS/HTTP proxy or Tor — and wipes everything with one panic button.

MV3 · Chrome ≥ 120 Edge · Chromium Firefox · event page GPL-3.0-or-later 0 telemetry endpoints
9
blocking categories
12
accent palettes
3
browsers, one source tree
24h
blocklist refresh cycle
0
telemetry, ever
Network transparency

Everything this extension ever sends

This is the complete list of outbound requests. There is no fourth row.

outbound — securityops-extension v10.1.0
Blocklist sync cdn.jsdelivr.net · raw.githubusercontent.comhagezi/dns-blocklists + chadmayfield NSFW list, refreshed every 24 h over HTTPS AUTOMATIC
IP lookup api.ipify.orgfills the IP card in the popup — runs only when you ask for it OPT-IN
Telemetry · analytics · crash reports —no endpoint exists in the codebase NONE
Verifiable in the source: every fetch in the background worker is HTTPS-only with timeout, retry and size caps. Full policy in the privacy policy.
Features

What ships in v10.1.0

Every feature is a toggle. Defaults are conservative; nothing activates a network request you didn't ask for.

Category blocking

Ads, trackers, malware, gambling, adult, social, scripts, media and the extra-aggressive Gigachad list — powered by hagezi/dns-blocklists and chadmayfield's NSFW list, refreshed every 24 h, with a hardcoded high-priority seed so popular ad hosts are blocked from the first second after install.

YouTube ad blocking

A page-world (world: MAIN) script patches JSON.parse, fetch and XMLHttpRequest before YouTube's own code runs, stripping ad placements from player responses. An isolated-world companion clicks skip buttons, fast-forwards unskippables and prunes ad DOM nodes.

Dark theme everywhere

Injected at document_start with your chosen accent color — 12 palettes from cyan to soft-violet. YouTube uses its native dark mode for compatibility. Fully reversible: deactivation walks the DOM and removes every inline style the extension set.

Parameter stripping & HTTPS

Removes utm_*, fbclid, gclid and friends from URLs before the request leaves, and upgrades plain HTTP to HTTPS — both implemented as declarative rules, not request interception.

Search & frontend redirects

Optional, per-toggle redirects: Google/Bing → SecurityOps Search, YouTube → Invidious, Reddit → Redlib. Off by default — your browser, your routes.

Proxy & Tor

Fixed-server SOCKS/HTTP proxy on Chromium, proxy.onRequest on Firefox. The TORANDO button points traffic at a local Tor daemon on 127.0.0.1:9050 — bring your own Tor, the extension never ships one.

Panic button

One click: clears all DNR rules, wipes browsing data and closes every tab. For the moment you need the browser to forget, immediately.

Logs view

See what was blocked, per host. Uses declarativeNetRequestFeedback where the browser exposes it, and an in-page blocked-resource detector (secops-reporter.js) where it doesn't — rate-limited so it never floods.

Free software, auditable

GPL-3.0-or-later, SPDX header in every source file, no minification in the repo, no eval, no innerHTML. The unpacked build you load is the code you can read.

Install

Get v10.1.0

Signed store builds are pending review. Until then, install the release ZIPs directly — and verify them first.

Cr
Chrome
MV3 · service worker · Chrome ≥ 120
  1. Download and unzip the Chrome package
  2. Open chrome://extensions, enable Developer mode
  3. Load unpacked → select the unzipped folder
⬇ securityops-10.1.0-chrome.zip
Ed
Edge
MV3 · service worker · Chromium
  1. Download and unzip the Edge package
  2. Open edge://extensions, enable Developer mode
  3. Load unpacked → select the unzipped folder
⬇ securityops-10.1.0-edge.zip
Fx
Firefox
MV3 · event page · gecko ID
  1. Download the Firefox package
  2. Open about:debugging#/runtime/this-firefox
  3. Load Temporary Add-on → select manifest.json from the ZIP, or install the signed build from AMO when available
⬇ securityops-10.1.0-firefox.zip
# verify before loading — SHA256SUMS is published with every release $ sha256sum -c SHA256SUMS ebc17fbcc41bae2ea095f149441469e2e9030b41cb08ce4e4ecfb0f49cbd45c2 securityops-10.1.0-chrome.zip ebc17fbcc41bae2ea095f149441469e2e9030b41cb08ce4e4ecfb0f49cbd45c2 securityops-10.1.0-edge.zip e2a2684c338ecfff74df46d27da3c4ef07257087a75d55a3370ba9be34688f09 securityops-10.1.0-firefox.zip

Chrome and Edge packages are byte-identical by design — one Chromium build, two names. Checksums file: SHA256SUMS.

# build from source — deps: bash, python3, zip, sha256sum # 1. download the source archive from the release page (HTTP git is disabled on this Forgejo) $ ./build.sh # → dist/{chrome,edge,firefox}/ + store zips + SHA256SUMS $ ./build.sh clean # → removes dist/

All three targets build from the single src/ tree; the Firefox manifest (event-page background, gecko ID) is derived from src/manifest.json at build time. Source archives: release page.

Architecture

How it works

MV3 without the usual MV3 fragility: declarative rules do the blocking, and three redundant channels keep state converged even when the worker sleeps.

One state of truth

Settings, whitelist and proxy config live in the background worker, mirrored to storage.sync. UI pages poll getStats and push patches through updateSettings; three fallback channels — runtime message, storage.onChanged, 1 s poll — keep content scripts converged even if the worker sleeps.

Declarative blocking

Dynamic DNR rules chunked at 1000 domains per rule inside per-category ID ranges, so toggling a category only touches its own range. Whitelisted domains get explicit allow rules plus excludedRequestDomains on every block rule — your exceptions always win.

Hardened by default

Message-action allowlist with sender validation, per-key settings validation, a domain regex on every blocklist/whitelist insertion, HTTPS-only fetches with timeout/retry/size caps, URL shape validation before logging, prototype-free hot maps, and no innerHTML, no eval anywhere.

Every permission, justified

The manifest asks for exactly what the features need — nothing speculative.

PermissionWhy it's needed
declarativeNetRequestApplies the block / redirect / HTTPS-upgrade rules in the browser's network layer
declarativeNetRequestFeedbackMatched-rule reporting that powers the Logs view, where the browser supports it
storagePersists settings, whitelist and proxy config; syncs them via storage.sync
proxyApplies the SOCKS/HTTP proxy configuration and the Tor preset
tabsBroadcasts theme changes to open tabs; closes every tab on panic
activeTabCurrent-tab actions triggered from the popup
browsingDataWipes browsing data when the panic button fires
webNavigationDetects navigations to attribute entries in the blocked-resource log
alarmsSchedules the 24 h blocklist refresh
<all_urls>Injects the dark-theme content script and enforces blocking on every site you visit
Security

Reporting & verification

Only the latest tagged release receives security fixes. Every release ships checksums.

Report a vulnerability

Email ethicalhacker@riseup.net — for sensitive reports, use the PGP key referenced in SECURITY.md. Include the affected version, browser + version, reproduction steps and an impact assessment. Acknowledgment within 72 hours. Non-security bugs go to the issue tracker.

Scope

In scope: the extension code in the repository — background worker, content scripts, popup/options pages, DNR rule generation, proxy handling, storage validation. Out of scope: upstream blocklist content (hagezi, chadmayfield), browser bugs, and the securityops.co website (report those separately).

Threat-model honesty: Security Ops hardens the browser; it does not anonymize you. It does not protect against browser fingerprinting, a compromised operating system, malicious extensions you install alongside it, or correlation by your network operator — for the Tor preset, the anonymity properties are Tor's, and only as strong as your local Tor daemon's configuration. Full policy in SECURITY.md.
Changelog

Release history

v10.1.02026-06-10
UI bug-fix and packaging release
Fixed: the Hide button on the IP card had no effect (display:flex overrode the hidden attribute); accent-swatch click handlers stacked on every popup refresh tick, firing duplicate settings updates; the options page rendered without icons for 11 labels/buttons; soft accent colors and white fell back to cyan on the options page; the background message handler could throw on malformed messages; window.applyIcons() early-hydration entry point now exists; the IP-lookup help text named the wrong service. Packaging: repository restructured into a buildable src/ tree with manifest.json under version control and a reproducible multi-browser build.sh producing Chrome/Edge/Firefox zips + SHA256SUMS, with the Firefox manifest derived at build time.
v10.0.02026-06
Initial public source drop
First public release of the source tree at git.securityops.co: per-browser builds from one source, MV3 manifests for Chrome/Edge (service worker, Chrome ≥ 120) and Firefox (event page, gecko ID), and the full popup/options UI.
FAQ

Questions, answered plainly

Two outbound destinations exist: blocklist downloads from jsDelivr/GitHub every 24 h, and the IP lookup against api.ipify.org that runs only when you use the IP card. There is no telemetry, analytics or crash-reporting endpoint in the codebase — see the Network transparency panel above and the privacy policy in the repo.
Network-level DNR rules block external ad networks, but YouTube serves ads from its own domain — so a page-world script registered with world: MAIN patches JSON.parse, fetch and XMLHttpRequest before YouTube's code runs and strips ad placements from player responses. An isolated-world companion handles whatever slips through: it clicks skip buttons, fast-forwards unskippables and removes ad DOM nodes.
The dark theme injects a content script at document_start on every page, and blocking has to apply everywhere to be useful. The permissions table above maps each manifest entry to the feature that needs it — nothing is requested speculatively, and the source is short enough to audit the claim yourself.
Every release publishes SHA256SUMS next to the ZIPs. Download both into the same directory and run sha256sum -c SHA256SUMS. The Chrome and Edge packages are byte-identical by design; Firefox differs because its manifest (event-page background, gecko ID) is derived at build time.
Yes — free as in freedom and price. GPL-3.0-or-later means you can use, study, modify and redistribute it, and anyone who distributes a modified version must publish their changes under the same terms. Every source file carries an SPDX header; the full license text is in LICENSE.
Security vulnerabilities: privately to ethicalhacker@riseup.net (PGP key referenced in SECURITY.md); you'll get an acknowledgment within 72 hours. Everything else: the issue tracker on Forgejo.