Extension Safety Check
Pick an unpacked Chrome extension folder. This page reads the files in your browser and looks for the usual red flags. Nothing is uploaded; the page makes no network requests.
or drop the folder here
What it checks
Permissions and site access
What the extension can reach: your tabs, cookies, history, or every website.
Network calls
Code that could send data somewhere: fetch, XMLHttpRequest, WebSocket, beacons, web addresses.
Hidden or remote code
Text run as code (eval), scripts loaded from the internet, minified or encoded code.
Files and fingerprints
Every file, with a SHA-256 fingerprint to compare against a published release.
What this can and can't tell you.
It's a static scan: it reads the code and the manifest, it doesn't run anything.
It catches the common warning signs (broad permissions, network calls, code loaded at runtime, hidden code),
but a clean result isn't a guarantee. The strongest check is still reading the code, which for small extensions takes minutes.