CRX to ZIP Converter

Drop in a .crx file and get the ZIP archive inside it. The header is removed by slicing the original bytes, so the output is exactly the package the extension was built from. Everything runs in your browser.

Files are processed locally in your browser and are not uploaded.

Tool

Choose a .crx package, or drop one onto this area. A plain .zipis accepted too — there is nothing to convert, so it is passed through with a note.

Drop a .crx file here

No file selected.

Files are processed locally in your browser and are not uploaded. Nothing inside the package is executed, installed, or rendered as HTML.

How to use

  1. Choose a .crx file, or drop one onto the file area.
  2. The tool reads the CRX header, shows you the format version and file size, and finds where the ZIP archive starts.
  3. Select "Download ZIP" to save the extracted archive. Nothing leaves your browser at any point.

How it works

A CRX file is a short binary header followed by an ordinary ZIP archive. This tool reads the header to find the exact byte offset where the ZIP begins, then copies those bytes into a new file.

Two header layouts are supported, and both were verified against real files. A CRX2 header declares the length of a public key and a signature, both of which precede the archive. A CRX3 header declares the total size of a block of metadata, which also precedes the archive. In each case the ZIP offset is 12 bytes plus the declared header data, and the tool checks that a real ZIP signature is present there before continuing.

The conversion is a byte slice, not a re-compression. That means the ZIP you get back is byte-for-byte the archive that was inside the CRX: no entry is re-encoded, dropped, reordered or renamed. It also means no ZIP-writing library is needed at all for this tool.

This tool does not verify the CRX signature. It reads the container so you can get at the archive; it makes no claim that a package is authentic, untampered, or safe to load.

Important limitations

  • Only CRX version 2 and version 3 headers are supported, and both were tested. A file with any other version number is reported as unsupported rather than guessed at.
  • The ZIP inside a CRX is not encrypted, so no password is needed and none is accepted. If a file cannot be opened, it is not a standard CRX package.
  • Nothing is executed. The archive is treated as data: paths are validated, contents are never run, and no HTML or JavaScript from the archive is ever rendered into the page.
  • An archive containing an unsafe path — an absolute path, a Windows drive letter, or a ".." traversal entry — is rejected as a whole rather than partially extracted, because a partially extracted package would no longer match the original extension.
  • Very large files are refused to protect your browser tab. Current limits: 64 MB, 128 MB total uncompressed, 32 MB per file, 5000 files, 24 directory levels, 512 characters per path.

Privacy and security

Files are processed locally in your browser and are not uploaded. The page contains no upload code, no analytics, and no third-party scripts. Clearing the page or closing the tab discards everything held in memory.

Frequently asked questions

Are my files uploaded anywhere?

No. The file is read with the browser File API into memory, the header is parsed, the archive is sliced, and the result is handed to the browser as a download. There is no upload endpoint on this site, and this page has no code that could send your file anywhere.

Why did my CRX get rejected?

Four things cause a rejection. The file is not a CRX at all, meaning it does not start with the four bytes "Cr24". The header is truncated, so the declared key or metadata length runs past the end of the file. The declared header length is not plausible. Or the bytes after the header are not a ZIP archive. The message names which of these it was.

Can this install the extension?

No. Converting a file changes nothing about your browser. To try an unpacked extension you would still use Chrome's own developer mode and "Load unpacked" on the resulting folder — a deliberate step you take yourself, after reading what is in the package.

Will the converted ZIP be identical to the original package?

Yes. The ZIP is copied out of the CRX byte for byte rather than being rebuilt, so it is the same archive the extension author shipped. The only difference between your input and your output is the removed CRX header.

What is the difference between a CRX and a ZIP?

Mostly that header, plus what the header contains: a signature that ties the package to a publisher. The CRX vs ZIP guide covers when the difference actually matters and when you can just work with a ZIP.