5 items
View and inspect Chrome extension source code, CRX files, permissions, network APIs, security risks, and manifest in real-time. Extension X-Ray is an advanced code inspection and security analysis tool designed for developers, security auditors, and extension creators. Inspect extension source files, analyze permissions, detect exposed credentials, and audit runtime network activity directly within Chrome's native Side Panel. Whether you are reviewing an extension before installation, auditing your own extension for Manifest V3 compliance, or inspecting bundled scripts, Extension X-Ray provides instant, sandboxed transparency without leaving your current tab. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ ⚡ KEY CAPABILITIES ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 🔍 In-Depth Source Code Inspection • Inspect extension packages directly from the Chrome Web Store URL, an Extension ID, or by dragging and dropping local files (.crx or .zip). • Built-in file explorer with syntax highlighting for scripts, markup, styles, and data files. • Tabbed code viewer with search and regex filtering across all package contents. • SHA-256 checksum verification for every file to verify package integrity. • Export uncompressed archives for offline review in your preferred editor. 🛡️ Permission & Attack Surface Analysis • Complete audit of requested extension permissions and API access. • Clear classification assessing whether permissions are necessary, broad, or sensitive. • Highlights broad host patterns and potential data exfiltration vectors. 🔐 Secret & Credential Detection • Scans bundled files using entropy analysis and pattern matching to identify accidentally committed secrets. • Detects exposed access keys, webhook URLs, authentication tokens, and private certificates. • Helps developers secure their code before publishing to the store. 📋 Manifest V3 Architecture & Compliance • Evaluates extensions for modern Manifest V3 standards. • Flags deprecated background pages, blocking request calls, and remote code patterns. • Verifies Content Security Policy (CSP) configurations and declarative rules. 🌐 Network & External Domain Mapping • Identifies external endpoints and domains contacted by extension scripts. • Categorizes third-party destinations such as backend services, content delivery networks, and analytics. 📐 Clean Rebuild Blueprint Generator • Summarizes extension component architecture and manifest definitions. • Exports structured architectural blueprints and prompts to assist developers in refactoring or modernizing extensions. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 🔒 PRIVACY & SECURITY FIRST ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ • 100% Client-Side Processing: Package decompression, code parsing, and security audits run locally inside your browser sandbox. • Zero Telemetry: No tracking, no external data harvesting, and no personal data collection. • Safe Inspection: View and analyze packages safely without executing extension background scripts or injecting them into your session. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 🚀 GETTING STARTED ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 1. Open Extension X-Ray from the Chrome toolbar or context menu to launch the Side Panel. 2. Navigate to an extension page or drop a local package file into the inspector. 3. Review the file tree, permission breakdown, security findings, and manifest details instantly.
Sep 8, 2026
rating_count is the Chrome Web Store ratings count, not a written-review count.
Media assets
Screenshots and videos on the listing.
Has promo video
Whether the listing includes at least one video.
Languages
Declared language locales.
Developer website
Listing exposes a developer website URL.
Contact email
Listing exposes a contact email.
Keyword in name
Case-insensitive substring match in the name.
Keyword in description
Case-insensitive substring match in the description.
Keyword occurrences in description
Count of case-insensitive occurrences in the description.
Category user-count percentile
Share of same-category extensions with fewer users (null if unknown).
These are transparent listing completeness / keyword signals, not a prediction of Chrome Web Store search ranking.