Ship extensions that pass review and keep their users
Security scanning, store-policy checks, market research and churn analytics — one toolkit.
The data behind the tools
Every tool is powered by the same cross-store extension intelligence
The extension lifecycle, covered
From the first market-research query to the last uninstall — seven tools, one API key.
MCP server
Catalog + scanner, inside your AI tools.
Learn more →Manifest generator
An MV3 manifest that passes review.
Learn more →Icon generator
An icon that stays readable at 16 px.
Learn more →Policy generator
A store-ready privacy policy, fast.
Learn more →CLI
Scan and predict store rejections before you ship.
Learn more →Pin guide
Illustrated steps that get your extension pinned.
Learn more →Uninstall feedback
A hosted exit survey for churn insight.
Learn more →How the platform actually behaves
The tools encode these rules. These posts explain them — permissions, MV3 migration, store policy and retention, written against the same catalog the tools read.
What 308K listings actually ask for
The permission footprint of the whole catalog, and where your request sits in it.
What Manifest V2 removal actually killed
Which APIs went away, and what the migration really costs.
chrome.offscreen: the DOM in an MV3 service worker
The supported way to keep DOM access after the background page went away.
declarativeNetRequest: blocking requests in MV3
Rule syntax, matching order and the limits that bite at review time.
Requesting optional permissions at runtime
Ask for the risky scopes when the user acts, not at install.
activeTab: the access with no warning
Why it is the cheapest permission you can ship, and what it really grants.
3,000 extensions collect data they never disclose
The gap between declared data practices and what the code does.
setUninstallURL: turn uninstalls into feedback
The one lifecycle hook that tells you why users left.
Questions people ask first
- Which of these tools are free?
- The manifest generator and the privacy policy generator run entirely in your browser and need no account and no API key. The MCP server and the CLI need a free API key, which comes with 10 catalog reads and 3 security scans, one time. After that you buy prepaid credit packs — there is no subscription and the credits do not expire.
- Do I need an API key to get started?
- Only for the MCP server and the CLI, because both read the catalog. Creating the key is free and takes one sign-in. The in-browser generators work without one.
- Which browsers do the tools cover?
- Chrome, Firefox and Edge. The manifest generator emits per-browser output, and the catalog behind every tool tracks listings across the Chrome Web Store, Firefox Add-ons and Edge Add-ons rather than Chrome alone.
- What does the CLI actually check?
- It runs 8 security scanners over your built extension and reports what a store reviewer is likely to flag — dangerous permissions, code injection patterns, undeclared data collection and manifest policy violations — before you submit rather than after a rejection.
- Can I use these inside an AI coding agent?
- Yes. The MCP server exposes cross-store search, security analysis, market research and pre-publish scanning as tools for Claude Code, Claude Desktop, Cursor and any other MCP client, so the agent writing your extension can also check it.
- Where does the data behind the tools come from?
- From the same cross-store catalog the whole platform runs on: extensions, versions and user reviews collected continuously from the Chrome, Firefox and Edge stores. Every tool reads that one dataset instead of a per-tool sample.
Your AI already writes the code. Now it knows the market.
One free API key unlocks the MCP server and the CLI. The manifest and policy generators are free and need no key at all.
No credit card · 10 free reads & 3 free scans, one-time.