viewhack

Extension viewer: check a browser extension before you install it

Got a .crx or .xpi from a developer's site, a forum or a colleague, or worried about one you already run after news of a hijacked extension? See what it asks for and what its code reaches for: every permission in one plain sentence, the sites it can read and change, where its updates come from, and the lines where it runs strings as code or loads scripts from other servers.

The file is read by this tab only. It is not uploaded, not installed and not run.

What it shows

What it cannot do

Useful to know about extension files

What a .crx and an .xpi are
Both are ZIP archives of the extension's folder. A .crx (Chrome, Edge, Brave, Opera) puts a signed header in front of the ZIP: the bytes Cr24, the format version (2, or 3 since Chrome 64 in 2018), then the public keys and signatures. An .xpi (Firefox) is a plain ZIP with Mozilla's signature files in META-INF/. Everything that matters is in manifest.json at the top of the ZIP.
How the ID is made
Chrome takes the SHA-256 hash of the developer's public key, keeps the first 16 bytes, and writes each of their 32 hex digits as a letter from a to p (0 is a, f is p). So a Chrome extension ID is always 32 letters from a to p, and anyone holding the key gets the same one. A CRX3 file also states the ID in its signed header; this page shows both and says whether they agree.
Checking one you already run
Chrome keeps installed extensions unpacked in its profile: Extensions/<ID>/<version>/ under %LOCALAPPDATA%\Google\Chrome\User Data\Default\ on Windows, ~/Library/Application Support/Google/Chrome/Default/ on a Mac and ~/.config/google-chrome/Default/ on Linux. Zip that version folder and drop the ZIP here. Firefox keeps each add-on as <id>.xpi in the extensions folder of your profile (about:support, "Profile Folder").
Getting the file from a store
Stores install rather than download. On addons.mozilla.org, right-click "Add to Firefox" in another browser and save the link: that is the .xpi. For the Chrome Web Store, the file Chrome itself fetches is at clients2.google.com/service/update2/crx?response=redirect&acceptformat=crx3&prodversion=130&x=id%3D<ID>%26uc with the 32-letter ID in place of <ID>.
Why updates matter more than the first install
An extension that was fine can turn bad in an update: in December 2024 attackers phished the Chrome Web Store login of Cyberhaven's developers and pushed a version that stole cookies and session tokens, and the same campaign hit dozens of other extensions. Earlier, in 2020, The Great Suspender was sold to a new owner and changed; Google removed it in 2021. Chrome installs updates silently, so an extension with <all_urls> and cookies is trusting its developer's account security as well as its developer.
Manifest V2 and V3
Manifest V3 forbids code loaded from a server in an extension's own pages, replaces the background page with a service worker, and moves request blocking to rules the browser applies (declarativeNetRequest). Chrome stopped running V2 extensions in 2025; Firefox runs both, and kept blocking webRequest. V3 does not stop a content script from adding a remote script to the page you are on, which is why that is flagged too.