Security & Risk Disclaimer

Effective: January 11, 2026Updated: June 30, 2026

Extenshi may provide automated security-related insights, safety scores, permission analyses, timelines, and scanning outputs (“Security Insights”). The safety score is presented as a coefficient on a 0–100 scale, computed as 100 − weighted findings score; a higher number means fewer or less severe automated findings, not a guarantee that an extension is safe.

Automated scanning infrastructure

Security Insights are generated through automated pipelines that may include multiple scanning tools and techniques, such as:

  • static code analysis tools (e.g., Semgrep, JSLuice, and similar),
  • permission and manifest analysis,
  • pattern-based heuristics and weighted scoring algorithms (which feed into the safety score),
  • third-party security databases and vulnerability feeds (where available),
  • AI-based analysis using large language models (LLMs), which may evaluate extension source code samples, manifest data, and other scanner results to produce security verdicts and confidence assessments.

Pipeline processing

Our automated infrastructure operates on scheduled intervals and may include retry mechanisms, health checks, and error handling. Extensions that fail to process may be marked with internal statuses (e.g., failed, quarantined) which reflect pipeline state, not security assessments.

Limitations and disclaimers

  • Security Insights are generated using automated systems and heuristics.
  • Security Insights may produce false positives or false negatives.
  • Security Insights do not constitute professional security auditing, penetration testing, malware analysis, or legal advice.
  • Scanning tools and techniques evolve over time; results may vary between scans of the same extension.
  • Historical security data (including data derived from web archives) may not reflect the current security posture of an extension.
  • Do not rely on Security Insights as the sole basis for critical decisions.

Third-party links and websites

Some Security Insights consider an extension’s outbound links — for example whether its store homepage or author website resolves to a site serving gambling, malware, or other harmful or unlawful content. Those external sites are operated by third parties and are not under our control; we do not endorse, sponsor, or assume responsibility for their content, legality, or practices, and the presence of a link in the catalog is not a recommendation. Where automated signals flag a destination as harmful, we may disable the outbound link and display it as plain, non-clickable text with a warning so users are neither directed to it nor exposed to its content. These signals are automated and may produce false positives or false negatives; following any external link is at your own risk. To report a harmful link, see our Content removal & takedown policy, and see the “Third-party links and websites” section of our Terms of Service.

User reviews of findings

Registered users may submit reviews of individual security findings to acknowledge or dispute them. Such reviews reflect the opinion of the submitting user and do not alter the automated scanning results. Extenshi does not verify the accuracy or completeness of user-submitted reviews.

Reviews that are approved by our team may be displayed publicly on the extension's catalog page alongside the relevant finding. By submitting a review, you acknowledge that your response text may become publicly visible if approved.

Extenshi does not guarantee that any extension is safe, compliant, or free of vulnerabilities. Use the information at your own risk, to the maximum extent permitted by law.

Questions: [email protected]