Skip to content

Extension Guard

Scan Chrome extension permissions for security risks with risk scoring, dangerous combination detection, and plain-English explanations

Extension Guard

Paste a JSON array, a comma-separated list, or one per line
Live analysis

Try a sample

How to find extension permissions

Method 1 — Chrome Web Store: Visit the extension's Chrome Web Store page → scroll down to "Permissions" section → copy the listed permissions.

Method 2 — Installed Extensions: Go to chrome://extensions → click "Details" on any extension → look for "Permissions" section.

Method 3 — manifest.json: If you have the extension source, find manifest.json and copy the "permissions" and "host_permissions" arrays.

Grade F, score 71 out of 100. Critical risk — this extension has excessive, dangerous permissions.

F
Risk score71/100
2 critical1 high1 medium2 low

Critical risk — this extension has excessive, dangerous permissions.

Dangerous permission combinations

Data Interceptioncritical

Can monitor all your browsing AND intercept all network traffic — a complete surveillance toolkit.

tabs + webRequest + <all_urls>

Traffic Manipulationcritical

Can intercept AND modify all web traffic — could inject malware, redirect payments, alter page content.

webRequest + webRequestBlocking

Permission details (6)

webRequestBlockingcriticalNetwork

Can block and modify web requests

Can silently alter or block any web request — used by ad blockers but also by malware.

<all_urls>criticalData Access

Can read and change data on ALL websites

Full access to every website you visit — can read passwords, inject scripts, and modify page content.

webRequesthighNetwork

Can intercept ALL web traffic

Can see, modify, or block every network request your browser makes.

tabsmediumBrowsing

Can see all your open tabs and URLs

Can monitor every website you visit in real-time by reading tab URLs.

storagelowStorage

Can store data locally

Stores extension settings and data in browser storage. Standard and safe.

contextMenuslowUI

Can add items to right-click menus

Adds options to your browser's context menu. Benign.

Understanding extension risks

Normal permissions

activeTab, storage, notifications, contextMenus — these are standard and low risk.

Watch carefully

tabs, history, downloads — legitimate uses exist but can reveal browsing habits.

Requires trust

cookies, webRequest, clipboardRead, scripting — only install from trusted developers.

Maximum caution

<all_urls> + webRequestBlocking + cookies — this combination can fully compromise your browsing.

Updated . Provided as is. Check the output before you rely on it in production.

How to use Extension Guard

  1. 1

    Paste extension permissions

    Copy the permissions from a Chrome extension's Web Store page, manifest.json, or chrome://extensions details. Paste as JSON array, comma-separated, or one per line.

  2. 2

    Click Analyze Permissions

    The security engine scores each permission individually and detects dangerous combinations that amplify risk. Results appear instantly.

  3. 3

    Review the risk report

    See your overall grade (A-F), risk score (0-100), color-coded permission breakdown, and any dangerous combination alerts with explanations.

  4. 4

    Understand each permission

    Every permission includes a plain-English explanation of what it allows and why it matters. Critical and high-risk permissions are flagged prominently.

  5. 5

    Copy or share the report

    Click 'Copy Report' to get a markdown-formatted security report you can share with your team or include in documentation.

Questions and answers

What is Extension Guard?
Chrome extension permissions are the capabilities an extension declares in its manifest, such as access to every site, cookies or network traffic. Paste a JSON array or a list of permissions here to get an overall risk score, a risk level and plain-English meaning for each one, and alerts for dangerous combinations.
How do I find a Chrome extension's permissions?
Visit the Chrome Web Store page and scroll to 'Permissions', go to chrome://extensions and click 'Details' on any extension, or check the manifest.json file for 'permissions' and 'host_permissions' arrays.
Is Extension Guard free and private?
Yes, Free to use and privacy-first by design. All security analysis runs entirely in your browser — your extension permissions are not sent to external servers.
What makes a Chrome extension dangerous?
Dangerous extensions request excessive permissions like <all_urls> (access to all websites), webRequest (intercept all traffic), and cookies (steal login sessions). Especially dangerous are COMBINATIONS of these permissions.
Does Extension Guard detect malicious extensions?
It analyzes permissions and permission combinations to flag potential risks. It cannot detect malicious code hidden within an extension — only the permissions it requests. A high risk score doesn't mean an extension IS malicious, but it CAN do more damage if compromised.
For AI agents: how to call this tool

Machine-readable contract, endpoints and examples. Humans can ignore this section.

Best Path For Builders

Browser workflow

Runs instantly in the browser with private local processing and copy/export-ready output.

Browser Workflow

This tool is optimized for instant in-browser execution with local data handling. Run it here and copy/export the output directly.

/extension-guard/

For automation planning, fetch the canonical contract at /api/tool/extension-guard.json.