Chrome Extension Inspector

Get a readable summary of an extension: its identity, the permissions it asks for, how it runs, and the resources it exposes. Paste a manifest or drop in a .crx or .zip package.

Files are processed locally in your browser and are not uploaded.

Tool

A .json, .crx or .zip file. Read locally, never uploaded.

Paste a manifest, or load a file above.

Waiting for a manifest.

How to use

  1. Paste manifest.json, or load a .json, .crx or .zip file.
  2. Select "Inspect extension".
  3. Read the four sections — basics, permissions, execution and resources — then the notices at the end for anything worth a second look.

How it works

The manifest is parsed in your browser with JSON.parse, which reads JSON as data and executes nothing. Nothing from the manifest is rendered as HTML.

The summary is assembled from the fields that describe what an extension is and how it behaves: identity, the three permission lists, background and content script configuration, the toolbar action, icons, web accessible resources and commands.

Notices are drawn from the same checks the Manifest V3 Validator uses, plus a few structural observations — a Manifest V2 file, broad host access, high-impact permissions, no icons, a background page in a Manifest V3 extension. Each one says what was found and what it usually means.

This is an informational tool. It describes what a manifest declares and does not assign a safety verdict, because a manifest alone cannot establish whether an extension is trustworthy — behaviour lives in code this tool does not read.

Important limitations

  • Describes the manifest, not the behaviour. Code in the service worker and content scripts is not analysed, executed, or rated.
  • Broad host access and high-impact permissions are surfaced because they are worth understanding, not because they are evidence of a problem. Many reputable tools need them.
  • Cannot tell you whether an extension was published by the developer it claims to be. That is what the CRX signature is for, and reading a signature is out of scope here.
  • Files referenced by the manifest are listed, not checked. A manifest pointing at a background.js that is not in the package is not detectable from the manifest alone.

Privacy and security

This tool runs entirely in your browser and has no upload path. Pasted text and chosen files are read with the File API and held in memory only while the page is open. Nothing is stored or sent anywhere.

Frequently asked questions

Can this tell me if an extension is safe?

No, and it is built not to pretend otherwise. It reports what a manifest declares. Whether an extension is trustworthy depends on what its code actually does and who publishes it, and neither is visible in a manifest. Treat this as a reading aid, then judge the extension on its own merits.

Why does it flag broad host access?

Because it is the single most consequential thing a manifest can ask for, and it is worth knowing. Blockers, translators, password managers and page enhancers all need it. The notice explains the capability and tells you what to check it against — not that something is wrong.

Can I inspect a .crx or .zip package directly?

Yes. Drop the file in and the manifest.json is read out of the archive in your browser. Nothing is extracted to disk and nothing is uploaded. The rest of the package is not read.

What is the difference between this and the Manifest Viewer?

The Viewer lists every field with its raw value, which is what you want when you are reading a specific key. The Inspector condenses a manifest into a summary with observations, which is what you want when you are orienting yourself in an unfamiliar extension.

Does it check for Manifest V3 problems?

Yes, the same checks the Manifest V3 Validator performs, summarised as notices. For the full list with suggested fixes, run the validator on the same manifest.