Trust

Don’t trust us. Check.

Four checks, from thirty seconds to a full rebuild. None of them require trusting a JarFlip server — there isn’t one.

1. Look at the permissions (30 seconds)

In the extension’s dashboard open Verify build, or open the browser’s extension page and choose Details → Site access. You should see:

  • Install-time permissions: cookies, storage, activeTab and (Chromium) sidePanel.
  • No “read and change all your data on all websites”. Site access is limited to the sites you approved, one at a time.

2. Read the content security policy (1 minute)

Open the extension’s manifest.json (unzip the package, or browse it from the extension’s details page in developer mode). The extension-pages policy must contain:

connect-src 'none'

That directive tells the browser to refuse every fetch, XHR, WebSocket and beacon from the extension’s pages — whatever the code tries.

3. Search the source for network calls (5 minutes)

The repository ships a check that fails the build if the extension contains network primitives, remote scripts or remote assets, and only allows links to this website:

pnpm install --frozen-lockfile
pnpm check-no-network

You can also search by hand for fetch(, XMLHttpRequest, WebSocket and sendBeacon in apps/extension. The extension has no runtime dependencies other than Preact and Preact Signals.

4. Rebuild it and compare hashes (15 minutes)

  1. Get the source for your version. Clone the repository and check out the tag that matches the version shown in the dashboard’s Verify build page.
  2. Build the package.
    pnpm install --frozen-lockfile
    pnpm -F extension zip
  3. Hash it.
    shasum -a 256 apps/extension/.output/*.zip
  4. Compare. The SHA-256 of each release package is published in that release’s notes. If they match, what you run is what is in the source.

Status: the public repository and the first tagged release are not live yet, so release hashes don’t exist yet. This page and the in-extension Verify build page will point to them when they do — until then, checks 1–3 apply to any build you make from source.

Questions

Found something that doesn’t add up? Write to support@pointerapps.net. Security reports are welcome — see security.txt.

Questions

Why can’t I just trust the store listing?+

Cookie extensions have been sold and turned into malware before. A listing can change owner or code overnight, so the checks below are things you can run yourself, on any version.

What if the hash on my machine doesn’t match?+

Don’t install it, and email support@pointerapps.net with the version, your OS and the hash you got. A mismatch can be as simple as a different Node or pnpm version, but it is always worth a look.

Stop logging in and out.
Start flipping.

Free and open source. No ads, no analytics, no network access.

Add to Chrome — freeFirefoxEdge