๐ŸŽ‰ New here? Use code WELCOME10 for 10% off any plan at checkout
All tools
betaChrome Extension Risk Scanner

Extension Scanner

Live permission + manifest analysis for Chrome extensions.

In the wildโ€” Extension Scanner runsโ€” Issues surfacedโ€” Countriesยท opt-in only

The problem

Extensions get install access in seconds. They can read every page, exfiltrate data, hijack sessions โ€” and most orgs have zero visibility into what they can actually do.

What it does

Submit an extension ID and we pull its live manifest straight from the Chrome Web Store, score every permission by risk, flag dangerous combinations (all-sites + code injection, all-sites + traffic interception), and summarize host reach. Or paste a manifest.json to score it offline.

Capabilities

  • Live manifest pull from the Chrome Web Store by ID
  • Permission risk scoring (0-100) with per-permission rationale
  • Dangerous-combination detection (inject-everywhere, traffic capture)
  • Manifest V2/V3 aware; flags off-store update URLs + remote CSP
  • Runs in the browser or as an npm package / CI gate

How you run it

Part of PlayCISO Pro: paste an extension ID (or a manifest) in the browser for an instant score, or install @playciso/extscan and fail CI on any critical/high permission risk.

Roadmap

  • Live Web Store manifest fetch + CRX parse
  • Permission scoring + dangerous combos
  • In-browser ID / manifest lookup
  • npm package + CI gate
  • Publisher history + Firefox/Edge support

FAQ

How do I check if a Chrome extension is safe?

Look at what it can actually do, not its star rating. The Extension Scanner pulls an extension's live manifest from the Chrome Web Store by ID and scores every permission it requests โ€” flagging high-risk ones (read all your data on every site, intercept traffic, inject code) and dangerous combinations that together enable data theft or session hijacking. A high score means the extension can do a lot of damage if it turns malicious or is sold to a bad actor.

Why are Chrome extension permissions a security risk?

An extension is installed in seconds and can be granted the ability to read and change every page you visit, capture what you type, read cookies and sessions, and talk to remote servers. Malicious or compromised extensions โ€” including previously-good ones bought by a new owner โ€” abuse exactly these permissions to exfiltrate data and hijack accounts, usually with no visible sign to the user.

What permission combinations are most dangerous?

The high-risk pairings are broad host access ("all sites") combined with content-script injection (run code on every page), or all-sites access combined with webRequest/traffic interception (read and modify network requests). Either combination turns an extension into something that can silently read, alter or exfiltrate everything you do in the browser โ€” which is why the scanner flags them specifically.

Included with any PlayCISO plan

Extension Scanner runs inside PlayCISO for subscribers. The source stays private โ€” no public repos, nothing to fork, nothing for attackers to study. Weekly, monthly, and yearly plans all include every tool.

Chrome Extension Risk Scanner โ€” Permission Audit ยท PlayCISO