one.zovo/crx-permission-risk

crx-permission-risk

Score the privilege a Chrome MV3 extension takes from its manifest, and diff permission sets.

1.0.0
Version
remote
Transport
3
Tools

Security review

Review passed

Reviewed Jan 1, 2000.

  • tools: 3 tools scanned
  • metadata: scanned

No findings.

Tools (3)

  • analyze_manifest

    Static privilege analysis of a Chrome MV3 manifest.json. Returns a 0-100 risk score, the permissions and host patterns that drive it, dangerous permission combinations, and MV3 policy problems (remote code, unsafe-eval, <all_urls> web_accessible_resources). Content-script matches are counted as host access even when host_permissions is empty.

  • explain_permission

    Returns the privilege weight (0-10) for a single Chrome extension permission or host pattern, what it actually grants, whether it triggers an install-time warning, and the narrower alternative if one exists.

  • compare_permission_sets

    Compares the permissions and host patterns of two versions of an extension. Reports the score delta, what was added or removed, and whether the change widens the install-time warning set, which makes Chrome disable the extension for existing users until they re-accept.