Private pre-submission checks for browser extensions

Catch review blockers before the store does.

Scan the exact ZIP you intend to submit. ExtensionGate checks its package, manifest, permissions, remote-code signals, data capabilities, and submission answers-without uploading your source.

  • No account
  • No source upload
  • Never executes your code
  • Chrome and Edge profiles

Static analysis cannot guarantee approval or legal compliance.

Release checkpoint
01Production ZIPextension-2.4.0.zip
02Submission answerspurpose · permissions · data
[evidence]
03Submission PacketChrome + Edge · source-linked
Local analysis

Run a real private preflight

This browser opens the package. ExtensionGate does not upload it, execute it, or follow URLs found inside it.

Store profile
Drop the ZIP hereor choose the exact build you intend to submitManifest V3 · root manifest.json · up to 25 MB
CRX, XPI, Manifest V2, Firefox, Safari, unzipped folders, and repository URLs are not analyzed in V1. Subfolders inside the ZIP are fine.Try the synthetic example
One package · six evidence lenses

What ExtensionGate checks

Deterministic checks lead. Context-sensitive signals stay labeled for manual review.

01

Package

  • Archive structure
  • Missing files
  • Invalid paths
02

Manifest

  • Manifest V3 fields
  • Version and locale
  • Referenced resources
03

Executable surfaces

  • Remote scripts
  • Content security policy
  • Worker pitfalls
04

Permissions

  • Broad host access
  • Sensitive capabilities
  • Observed use
05

Data signals

  • Data capabilities
  • Outbound origins
  • Disclosure questions
06

Submission consistency

  • Single purpose
  • Listing and privacy
  • Reviewer notes
Evidence, not a mystery score

See the file, official basis, and smallest next action.

Severity describes impact. Confidence describes what static analysis can prove. ExtensionGate keeps those dimensions separate.

View the full synthetic report
BlockerEG-RHC-001Chrome + EdgeCertain

Remote script is loaded by an extension page

popup.html:18
<script src="https://cdn.example.com/widget.js"></script>
Smallest next action

Bundle the dependency in the package and reference a relative path.

Official source linkedReviewed 2026-07-29
The consistency gate

Your submission should tell one story.

Package evidence and developer answers are different kinds of facts. ExtensionGate compares them without turning a static signal into an accusation.

Developer answer
“No data leaves the device.”
Package evidence
sendBeacon(
  "https://telemetry.example.com/collect",
  payload
)
Review required

A transmission signal conflicts with the supplied answer. Confirm what is sent, then update the extension or disclosure.

One package · two store lenses

Shared Chromium foundation. Separate review work.

Chrome and Edge share much of the extension model, but their forms, metadata, policies, and supported capabilities are not identical.

Primary V1 profile

Chrome Web Store

Manifest V3, remote code, permissions, data, and notification guidance.

Explore Chrome coverage →
Supported static lens

Microsoft Edge Add-ons

Porting, privacy fields, branding, testability, and certification notes.

Explore Edge coverage →
Local-processing architecture

Package data has no server path.

The worker can parse package content and return sanitized findings to this page. It cannot make network requests or execute package code.

Read the security design
  1. 1
    Your browser reads the ZIP

    The user-selected file enters browser memory.

  2. 2
    A dedicated worker parses inert text

    Archive and parser limits contain hostile input.

  3. 3
    The report and packet stay local

    Export creates a local Blob. Closing the tab clears state.

Free safety · paid workflow

Fix the extension for free.

See pricing
Free Preflight$0

Complete supported blocker and security findings for one store profile.

  • Evidence and remediation
  • Permission and origin inventories
  • Official policy sources
  • No account or source upload
Run a free preflight
Release Pass$19 one time

Thirty days of local Chrome and Edge submission workflow.

  • Cross-artifact mismatch review
  • Permission and reviewer-note drafts
  • Store-specific checklists
  • Markdown, JSON, and print exports
Review the Release Pass

Static analysis has a boundary.

ExtensionGate cannot inspect private backends, reproduce every reviewer decision, test runtime behavior, certify legal compliance, detect every malicious behavior, or guarantee approval.

Questions before you scan

Trust is part of the product.

The useful answer is the precise one-even when the answer is a limitation.

Is my extension uploaded?

No. The ZIP, paths, manifest, source, findings, detected domains, and answers remain in browser memory.

Does a clean report guarantee approval?

No. “No static blockers found” means only that the supported static rules completed without a blocker, action, or unresolved review finding.

Does ExtensionGate execute my extension?

No. Package files are decompressed within safety limits and parsed as inert text in a dedicated local worker.

Which package formats are supported?

V1 accepts a Chromium Manifest V3 ZIP with manifest.json at the archive root. CRX, XPI, repositories, Manifest V2, Firefox, and Safari are not analyzed.

Does it detect malware?

No. It can flag supported high-confidence security patterns and exposed secrets, but it does not certify an extension as malware-free or safe.

Why pay if the free scan is complete?

Free includes every supported blocker and security finding for one store. The Release Pass adds Chrome/Edge comparison, disclosure reconciliation, drafts, checklists, and exports.

Does it modify my extension?

No. ExtensionGate reports evidence and next actions. It never rewrites the package.

Does it support Firefox?

No. Firefox needs its own official tooling, policies, and fixture suite. It is not a V1 support claim.

Is it affiliated with browser stores?

No. ExtensionGate is an independent BigYap product and is not affiliated with Google, Microsoft, Mozilla, Chrome, Edge, or their stores.

What happens when the tab closes?

The free report and questionnaire disappear by default. Export a packet if you want to keep it. Source and reports are not persisted.

How do refunds work?

The planned launch policy is a 14-day refund request window when the packet was not useful. Live sales stay disabled until the seller and final terms are configured.

Your next release

Scan the build you are about to submit.

No account. No source upload. Every supported free finding remains visible.

Start a private preflight