Package
- Archive structure
- Missing files
- Invalid paths
Scan the exact ZIP you intend to submit. ExtensionGate checks its package, manifest, permissions, remote-code signals, data capabilities, and submission answers-without uploading your source.
Static analysis cannot guarantee approval or legal compliance.
extension-2.4.0.zippurpose · permissions · dataChrome + Edge · source-linkedThis browser opens the package. ExtensionGate does not upload it, execute it, or follow URLs found inside it.
manifest.json · up to 25 MBDeterministic checks lead. Context-sensitive signals stay labeled for manual review.
Severity describes impact. Confidence describes what static analysis can prove. ExtensionGate keeps those dimensions separate.
View the full synthetic reportpopup.html:18
<script src="https://cdn.example.com/widget.js"></script>Bundle the dependency in the package and reference a relative path.
Package evidence and developer answers are different kinds of facts. ExtensionGate compares them without turning a static signal into an accusation.
“No data leaves the device.”
sendBeacon(
"https://telemetry.example.com/collect",
payload
)A transmission signal conflicts with the supplied answer. Confirm what is sent, then update the extension or disclosure.
Chrome and Edge share much of the extension model, but their forms, metadata, policies, and supported capabilities are not identical.
Manifest V3, remote code, permissions, data, and notification guidance.
Explore Chrome coverage →Supported static lensPorting, privacy fields, branding, testability, and certification notes.
Explore Edge coverage →The worker can parse package content and return sanitized findings to this page. It cannot make network requests or execute package code.
Read the security designThe user-selected file enters browser memory.
Archive and parser limits contain hostile input.
Export creates a local Blob. Closing the tab clears state.
Complete supported blocker and security findings for one store profile.
Thirty days of local Chrome and Edge submission workflow.
ExtensionGate cannot inspect private backends, reproduce every reviewer decision, test runtime behavior, certify legal compliance, detect every malicious behavior, or guarantee approval.
The useful answer is the precise one-even when the answer is a limitation.
No. The ZIP, paths, manifest, source, findings, detected domains, and answers remain in browser memory.
No. “No static blockers found” means only that the supported static rules completed without a blocker, action, or unresolved review finding.
No. Package files are decompressed within safety limits and parsed as inert text in a dedicated local worker.
V1 accepts a Chromium Manifest V3 ZIP with manifest.json at the archive root. CRX, XPI, repositories, Manifest V2, Firefox, and Safari are not analyzed.
No. It can flag supported high-confidence security patterns and exposed secrets, but it does not certify an extension as malware-free or safe.
Free includes every supported blocker and security finding for one store. The Release Pass adds Chrome/Edge comparison, disclosure reconciliation, drafts, checklists, and exports.
No. ExtensionGate reports evidence and next actions. It never rewrites the package.
No. Firefox needs its own official tooling, policies, and fixture suite. It is not a V1 support claim.
No. ExtensionGate is an independent BigYap product and is not affiliated with Google, Microsoft, Mozilla, Chrome, Edge, or their stores.
The free report and questionnaire disappear by default. Export a packet if you want to keep it. Source and reports are not persisted.
The planned launch policy is a 14-day refund request window when the packet was not useful. Live sales stay disabled until the seller and final terms are configured.
No account. No source upload. Every supported free finding remains visible.
Start a private preflight