Skip to main content
Application security tools

Application security / FREE TOOL

Browser extension review

Review a browser extension manifest for permission scope, injected scripts, messaging boundaries, and update settings.

Local review / optional AI

01 Your input

Local processing only. Maximum file size: 2 MB.

02 Your results

A closer look starts here.

Add your input and run the check. We will show the observations and explain what needs review.

 

A QUICK WALKTHROUGH

How to use it

  1. 01Select or paste the extension manifest.json file.
  2. 02Review required and optional capabilities, host scope and trust boundaries.
  3. 03Compare these declarations with the extension purpose and inspect its JavaScript using the JavaScript review tool.

What this check can tell you

Inspects manifest declarations only, without installing an extension or opening a store listing. It does not inspect an archive, publisher identity, bundled code or runtime behavior, and cannot determine whether an extension is malicious. Review extracted JavaScript separately. Maximum manifest size: 200,000 characters.

The initial review processes files in this tab. If you choose the optional AI summary, the displayed findings are sent to Cloudflare AI; your raw file, result tables and decoded token claims are excluded.

Chrome extension permission guidance