Nishi FamilyCompare › Ethical Clean-Serve -- safe delivery of the hostile web (SOTA)

Nishi vs the Field

Ethical Clean-Serve -- safe delivery of the hostile web — the full field, measured, sourced.

Nishi clean-serve (server-side attack neutralization + safe-ad preservation + native media + machine receipt) vs the ad-block / shield / reader / archive field

How this is scored. This is a state-of-the-art comparison across the FULL competitor field: quantitative axes carry measured / published numbers (Nishi’s column is our own measurement, competitors are researcher-sourced), grade axes use Best / Yes / Part / No. Every axis carries a source note. No single vanity ‘coverage’ score — the honest picture is per-axis. Where Nishi is under SOTA, that is filed work with an owner, never ‘by design’ (operator law: less-than-SOTA is never design) — every sub-SOTA axis maps to a frontier rung; the only legitimate divergence from the field is a measured exceed bet that carries its number (e.g. no-float determinism). The climb is the plan.
CapabilityNishiuBlock-OriginBrave-ShieldsPrivacy-BadgerAdBlock-PlusNoScriptReader-ViewWeb-LightBrowsertrixNotes / source
User safety - attack neutralization
Server-side neutralization - page JS never runs in your browserBestNoNoNoNoNoPartYesYesthe keystone - active content stripped on the server so the hostile page never executes in the user context; every browser extension is client-side and only blocks network requests
Strip all inline scriptsYesPartPartNoNoBestYesYesPartcs_clean_page removes every script block; NoScript blocks all JS execution; uBlock blocks by list not wholesale
Remove active third-party iframesYesYesYesPartPartYesYesYesYesiframe embed and object stripped; most blockers gate by list
Neutralize meta-refresh and javascript-URI redirectsYesPartPartNoNoYesYesPartPartmalvertising auto-redirect vectors removed; network blockers rarely touch inline redirect
Strip inline event handlers on-star=YesNoNoNoNoPartYesPartNoonclick onload onerror exec vectors removed at the source; network blockers do not rewrite inline HTML
Reverse-tabnabbing protection rel-noopenerYesPartYesNoNoPartYesPartNorel noopener noreferrer nofollow injected on every anchor; modern browsers default some of this
Tracker and beacon blockingPartBestYesBestYesPartYesYesParthonest gap - nx_web_filter is a seed table not EasyPrivacy scale; uBlock and Privacy Badger lead
Cryptominer blockingYesYesYesPartYesPartYesYesPartminer request URLs neutralized; uBlock and Brave block by list
Popunder and popup suppressionYesYesYesPartYesPartYesYesPartpopunder vectors removed
SSRF guard on the fetch proxyYesNoNoNoNoNoNoPartPartclean-serve is a public fetch proxy that refuses private loopback and internal targets by construction; extensions are not proxies
Fingerprint resistance depthNoPartBestPartNoNoPartPartNohonest gap - zero-JS view removes JS fingerprinting but no canvas font or WebGL spoofing; Brave randomizes fingerprints
Filter-list breadth EasyList-scaleNoBestYesPartBestPartNoNoNohonest gap - seed table only; uBlock EasyList EasyPrivacy and AdBlock are the mature bar
Real-time filter-list auto-updateNoBestYesYesBestPartNoNoNohonest gap - static seed table with no subscription auto-refresh
Anti-adblock scriptlet and surrogate defenseNoBestYesNoYesPartNoNoNohonest gap - uBlock injects scriptlets and surrogates to defeat anti-adblock; clean-serve does not
Rich cosmetic element hidingPartBestYesPartYesPartYesPartNopartial - only a minimal age-gate and consent-overlay CSS neutralizer today; uBlock cosmetic filtering is rich
DNS or network-wide blockingNoPartYesNoPartNoNoNoNohonest gap - clean-serve is per-fetch server-side, not a DNS sinkhole or network filter
Site monetization - the win-win-win
Preserve the site safe ads - SANITIZE not blockBestNoNoNoPartNoNoNoNoUNIQUE - an ad kept as an inert static creative so the site earns a real impression; all others block ads or Brave substitutes its own and AdBlock Acceptable-Ads is pay-to-whitelist not per-ad
Advertiser-honest real impressionYesNoNoNoPartNoNoNoNothe preserved ad is a genuine paid impression not a faked or surrogate success
No pay-to-whitelist schemeYesYesYesYesNoYesYesYesYesper-ad sanitize needs no payment; AdBlock Plus Acceptable-Ads charges large advertisers
Transparency
Machine-readable safety receiptBestNoNoNoNoNoNoNoNoUNIQUE - cs_receipt_json emits a per-page JSON receipt of attacks neutralized and ads preserved; no incumbent emits an auditable receipt
Per-page attack auditYesPartNoNoNoNoNoNoPartcounts every neutralized vector per page; the uBlock logger is the closest
Delivery
Native HTML5 media deliveryYesNoNoNoNoNoPartPartNoextracts the stream including KVS de-obfuscation into a bare video element; reader modes sometimes keep media
Zero-JS deterministic clean viewYesNoNoNoNoPartYesYesYesthe delivered page is static zero-JS; reader modes and the defunct Web Light are the closest
Content preserved - article intactYesYesYesYesYesPartPartYesYestext images and DOM pass through byte-for-byte; reader modes over-strip
Neutrality and policy
Difficult-but-legal site served not derankedBestNoNoNoNoNoNoPartNoneutral serve of a hostile-but-legal site instead of a search-engine derank or a browser block page - a policy stance no blocker takes
Fetch and access - what to improve
Session and cookie-jar fetchYesNoNoNoNoNoNoPartYesff_core cookie jar carries session and consent cookies across redirects; Browsertrix headless Chrome has full cookies
Pass Cloudflare JS challengeNoNoNoNoNoNoNoNoBesthonest gap and research opp - CF managed-challenge JS proof-of-work not passed; Browsertrix real headless Chrome passes; own arc
Run framework JS to resolve player mediaPartNoNoNoNoNoNoNoBesthonest partial - minified jQuery 3.7.1 LOADS in the sovereign JS VM but vsf_sniff_url_net is not yet wired into clean-serve (F108d); Browsertrix runs real Chrome
Geo and split-tunnel unblockingPartNoNoNoNoNoNoNoPartdesign principle - slow-exit control-plane and direct data-plane - not yet shipped
Archive and durability
Link-rot archive capture WARCPartNoNoNoNoNoNoPartBestnx_web_archive present but not Browsertrix or Wayback scale or JS-render fidelity (honest gap)
Sovereignty
Zero third-party dependencyBestNoNoNoNoNoNoNoNoown language compiler TLS 1.3 fetch filter and renderer; every competitor is a browser extension or Chromium
Own sovereign TLS 1.3 fetch stackYesNoNoNoNoNoNoNoNonx_https_fetch_follow plus own x509 chacha and aes; competitors ride the OS or browser TLS
User config UI - element picker and per-site rulesNoBestYesPartYesPartPartNoNohonest gap - no element picker or per-site settings UI; the uBlock advanced UI is the bar
Community filter-list subscriptionsNoBestYesPartBestPartNoNoNohonest gap - no filter-list subscription ecosystem
Browser or mobile clientNoBestBestYesBestPartYesNoParthonest gap - server-side only, no extension or mobile app
Scale and delivery - quantitative
Scripts neutralized per page measured live1 to 46 measuredby-listby-listn/aby-listall-blockedall-strippedserver-transcodecapturedreceipts this session example 0 HN 1 guardian 19 arstechnica 25 techcrunch 43 nytimes 46
Safe ads preserved per page0 to 2 measured0 all-blocked0 own-ads0 all-blockedwhitelist-only0 all-blocked000clean-serve is the only column not zero by design
Filter rules maintainedseed table300k+ EasyListEasyList+heuristic no-listEasyList+user rulesn/an/an/ahonest gap - rule breadth is the maturity axis to close
Third-party runtime dependencies0browser+extChromiumbrowser+extbrowser+extbrowser+extbrowserGoogle infraPython+Chromesovereign stack with zero third-party
8 competitors39 axes4 quantitativeNishi Best on 5
Honest verdict. Clean-serve is narrow-but-deep: on a handful of STRUCTURAL axes it is alone in the field, and on breadth and ecosystem it is young and trails the mature blockers. Alone: it runs the hostile page's active content server-side, so the page's JavaScript never executes in the user's browser at all -- every extension here is client-side, meaning the malicious JS still runs in your tab and they only block network requests; it is the only tool that preserves the site's safe ads as inert static creatives (a SANITIZE verdict) so a difficult-but-legal site still earns while the user stays safe, where everyone else blocks all ads or substitutes their own; it emits a machine-readable safety receipt per page that no incumbent produces; it serves difficult-but-legal sites neutrally instead of deranking or blocking them; and it runs on a zero-third-party sovereign stack (own TLS 1.3, fetch, filter, renderer). It trails, honestly, on what a decade-old blocker has: no EasyList-scale filter lists, no element-picker or per-site config UI, no browser or mobile client, no community filter subscriptions, no anti-adblock scriptlets, no deep fingerprint spoofing, no DNS-level blocking, and it does not yet pass Cloudflare JS challenges or run framework JS to resolve player media inside clean-serve (9 honest No axes vs 5 Best -- the anti-vanity gate). Those gaps are the ranked research backlog: filter-list breadth, JS-exec-in-clean-serve (F108d), Cloudflare-challenge, fingerprint depth, archive scale. Measured live this session: 5 news/tech sites cleaned safe, 1 to 46 scripts and 0 to 4 trackers neutralized each.

Generated by nx_swcompare_sota from knowledge/compare/cleanserve.sota — quantitative axes measured/sourced; researcher-fed (nx_swcompare_research). Zero JS, zero trackers.