Privacy-first browser hardening. One source tree, three browsers, zero telemetry.
Security Ops blocks ads, trackers and malware at the network layer with declarativeNetRequest, darkens every site with your accent color, strips YouTube ads before the player sees them, rewrites tracking parameters, upgrades HTTP to HTTPS, routes traffic through a SOCKS/HTTP proxy or Tor — and wipes everything with one panic button.
Everything this extension ever sends
This is the complete list of outbound requests. There is no fourth row.
fetch in the background worker is HTTPS-only with timeout, retry and size caps. Full policy in the privacy policy.What ships in v10.1.0
Every feature is a toggle. Defaults are conservative; nothing activates a network request you didn't ask for.
Category blocking
Ads, trackers, malware, gambling, adult, social, scripts, media and the extra-aggressive Gigachad list — powered by hagezi/dns-blocklists and chadmayfield's NSFW list, refreshed every 24 h, with a hardcoded high-priority seed so popular ad hosts are blocked from the first second after install.
YouTube ad blocking
A page-world (world: MAIN) script patches JSON.parse, fetch and XMLHttpRequest before YouTube's own code runs, stripping ad placements from player responses. An isolated-world companion clicks skip buttons, fast-forwards unskippables and prunes ad DOM nodes.
Dark theme everywhere
Injected at document_start with your chosen accent color — 12 palettes from cyan to soft-violet. YouTube uses its native dark mode for compatibility. Fully reversible: deactivation walks the DOM and removes every inline style the extension set.
Parameter stripping & HTTPS
Removes utm_*, fbclid, gclid and friends from URLs before the request leaves, and upgrades plain HTTP to HTTPS — both implemented as declarative rules, not request interception.
Search & frontend redirects
Optional, per-toggle redirects: Google/Bing → SecurityOps Search, YouTube → Invidious, Reddit → Redlib. Off by default — your browser, your routes.
Proxy & Tor
Fixed-server SOCKS/HTTP proxy on Chromium, proxy.onRequest on Firefox. The TORANDO button points traffic at a local Tor daemon on 127.0.0.1:9050 — bring your own Tor, the extension never ships one.
Panic button
One click: clears all DNR rules, wipes browsing data and closes every tab. For the moment you need the browser to forget, immediately.
Logs view
See what was blocked, per host. Uses declarativeNetRequestFeedback where the browser exposes it, and an in-page blocked-resource detector (secops-reporter.js) where it doesn't — rate-limited so it never floods.
Free software, auditable
GPL-3.0-or-later, SPDX header in every source file, no minification in the repo, no eval, no innerHTML. The unpacked build you load is the code you can read.
Get v10.1.0
Signed store builds are pending review. Until then, install the release ZIPs directly — and verify them first.
- Download and unzip the Chrome package
- Open
chrome://extensions, enable Developer mode - Load unpacked → select the unzipped folder
- Download and unzip the Edge package
- Open
edge://extensions, enable Developer mode - Load unpacked → select the unzipped folder
- Download the Firefox package
- Open
about:debugging#/runtime/this-firefox - Load Temporary Add-on → select
manifest.jsonfrom the ZIP, or install the signed build from AMO when available
Chrome and Edge packages are byte-identical by design — one Chromium build, two names. Checksums file: SHA256SUMS.
All three targets build from the single src/ tree; the Firefox manifest (event-page background, gecko ID) is derived from src/manifest.json at build time. Source archives: release page.
How it works
MV3 without the usual MV3 fragility: declarative rules do the blocking, and three redundant channels keep state converged even when the worker sleeps.
One state of truth
Settings, whitelist and proxy config live in the background worker, mirrored to storage.sync. UI pages poll getStats and push patches through updateSettings; three fallback channels — runtime message, storage.onChanged, 1 s poll — keep content scripts converged even if the worker sleeps.
Declarative blocking
Dynamic DNR rules chunked at 1000 domains per rule inside per-category ID ranges, so toggling a category only touches its own range. Whitelisted domains get explicit allow rules plus excludedRequestDomains on every block rule — your exceptions always win.
Hardened by default
Message-action allowlist with sender validation, per-key settings validation, a domain regex on every blocklist/whitelist insertion, HTTPS-only fetches with timeout/retry/size caps, URL shape validation before logging, prototype-free hot maps, and no innerHTML, no eval anywhere.
Every permission, justified
The manifest asks for exactly what the features need — nothing speculative.
| Permission | Why it's needed |
|---|---|
declarativeNetRequest | Applies the block / redirect / HTTPS-upgrade rules in the browser's network layer |
declarativeNetRequestFeedback | Matched-rule reporting that powers the Logs view, where the browser supports it |
storage | Persists settings, whitelist and proxy config; syncs them via storage.sync |
proxy | Applies the SOCKS/HTTP proxy configuration and the Tor preset |
tabs | Broadcasts theme changes to open tabs; closes every tab on panic |
activeTab | Current-tab actions triggered from the popup |
browsingData | Wipes browsing data when the panic button fires |
webNavigation | Detects navigations to attribute entries in the blocked-resource log |
alarms | Schedules the 24 h blocklist refresh |
<all_urls> | Injects the dark-theme content script and enforces blocking on every site you visit |
Reporting & verification
Only the latest tagged release receives security fixes. Every release ships checksums.
Report a vulnerability
Email ethicalhacker@riseup.net — for sensitive reports, use the PGP key referenced in SECURITY.md. Include the affected version, browser + version, reproduction steps and an impact assessment. Acknowledgment within 72 hours. Non-security bugs go to the issue tracker.
Scope
In scope: the extension code in the repository — background worker, content scripts, popup/options pages, DNR rule generation, proxy handling, storage validation. Out of scope: upstream blocklist content (hagezi, chadmayfield), browser bugs, and the securityops.co website (report those separately).
Release history
display:flex overrode the hidden attribute); accent-swatch click handlers stacked on every popup refresh tick, firing duplicate settings updates; the options page rendered without icons for 11 labels/buttons; soft accent colors and white fell back to cyan on the options page; the background message handler could throw on malformed messages; window.applyIcons() early-hydration entry point now exists; the IP-lookup help text named the wrong service. Packaging: repository restructured into a buildable src/ tree with manifest.json under version control and a reproducible multi-browser build.sh producing Chrome/Edge/Firefox zips + SHA256SUMS, with the Firefox manifest derived at build time.git.securityops.co: per-browser builds from one source, MV3 manifests for Chrome/Edge (service worker, Chrome ≥ 120) and Firefox (event page, gecko ID), and the full popup/options UI.Documentation
Features, install, build, architecture notes ⛨ SECURITY.md
Disclosure policy, scope, verification ◉ Privacy policy
What leaves the browser, and when § LICENSE
GPL-3.0 — full canonical text ⌘ build.sh
Reproducible multi-browser release builder ⬇ Releases
Signed-by-checksum ZIPs for all three browsers
Questions, answered plainly
api.ipify.org that runs only when you use the IP card. There is no telemetry, analytics or crash-reporting endpoint in the codebase — see the Network transparency panel above and the privacy policy in the repo.world: MAIN patches JSON.parse, fetch and XMLHttpRequest before YouTube's code runs and strips ad placements from player responses. An isolated-world companion handles whatever slips through: it clicks skip buttons, fast-forwards unskippables and removes ad DOM nodes.document_start on every page, and blocking has to apply everywhere to be useful. The permissions table above maps each manifest entry to the feature that needs it — nothing is requested speculatively, and the source is short enough to audit the claim yourself.SHA256SUMS next to the ZIPs. Download both into the same directory and run sha256sum -c SHA256SUMS. The Chrome and Edge packages are byte-identical by design; Firefox differs because its manifest (event-page background, gecko ID) is derived at build time.LICENSE.