Extension Guard
Scan Chrome extension permissions for security risks with risk scoring, dangerous combination detection, and plain-English explanations
Extension Guard
Try a sample
How to find extension permissions
Method 1 — Chrome Web Store: Visit the extension's Chrome Web Store page → scroll down to "Permissions" section → copy the listed permissions.
Method 2 — Installed Extensions: Go to chrome://extensions → click "Details" on any extension → look for "Permissions" section.
Method 3 — manifest.json: If you have the extension source, find manifest.json and copy the "permissions" and "host_permissions" arrays.
Grade F, score 71 out of 100. Critical risk — this extension has excessive, dangerous permissions.
Critical risk — this extension has excessive, dangerous permissions.
Dangerous permission combinations
Can monitor all your browsing AND intercept all network traffic — a complete surveillance toolkit.
tabs + webRequest + <all_urls>
Can intercept AND modify all web traffic — could inject malware, redirect payments, alter page content.
webRequest + webRequestBlocking
Permission details (6)
webRequestBlockingcriticalNetworkCan block and modify web requests
Can silently alter or block any web request — used by ad blockers but also by malware.
<all_urls>criticalData AccessCan read and change data on ALL websites
Full access to every website you visit — can read passwords, inject scripts, and modify page content.
webRequesthighNetworkCan intercept ALL web traffic
Can see, modify, or block every network request your browser makes.
tabsmediumBrowsingCan see all your open tabs and URLs
Can monitor every website you visit in real-time by reading tab URLs.
storagelowStorageCan store data locally
Stores extension settings and data in browser storage. Standard and safe.
contextMenuslowUICan add items to right-click menus
Adds options to your browser's context menu. Benign.
Understanding extension risks
Normal permissions
activeTab, storage, notifications, contextMenus — these are standard and low risk.
Watch carefully
tabs, history, downloads — legitimate uses exist but can reveal browsing habits.
Requires trust
cookies, webRequest, clipboardRead, scripting — only install from trusted developers.
Maximum caution
<all_urls> + webRequestBlocking + cookies — this combination can fully compromise your browsing.
Updated . Provided as is. Check the output before you rely on it in production.
How to use Extension Guard
- 1
Paste extension permissions
Copy the permissions from a Chrome extension's Web Store page, manifest.json, or chrome://extensions details. Paste as JSON array, comma-separated, or one per line.
- 2
Click Analyze Permissions
The security engine scores each permission individually and detects dangerous combinations that amplify risk. Results appear instantly.
- 3
Review the risk report
See your overall grade (A-F), risk score (0-100), color-coded permission breakdown, and any dangerous combination alerts with explanations.
- 4
Understand each permission
Every permission includes a plain-English explanation of what it allows and why it matters. Critical and high-risk permissions are flagged prominently.
- 5
Copy or share the report
Click 'Copy Report' to get a markdown-formatted security report you can share with your team or include in documentation.
Questions and answers
What is Extension Guard?
How do I find a Chrome extension's permissions?
Is Extension Guard free and private?
What makes a Chrome extension dangerous?
Does Extension Guard detect malicious extensions?
For AI agents: how to call this tool
Machine-readable contract, endpoints and examples. Humans can ignore this section.
Best Path For Builders
Browser workflow
Runs instantly in the browser with private local processing and copy/export-ready output.
Browser Workflow
This tool is optimized for instant in-browser execution with local data handling. Run it here and copy/export the output directly.
/extension-guard/
For automation planning, fetch the canonical contract at /api/tool/extension-guard.json.