Don’t trust us. Check.
Four checks, from thirty seconds to a full rebuild. None of them require trusting a JarFlip server — there isn’t one.
1. Look at the permissions (30 seconds)
In the extension’s dashboard open Verify build, or open the browser’s extension page and choose Details → Site access. You should see:
- Install-time permissions:
cookies,storage,activeTaband (Chromium)sidePanel. - No “read and change all your data on all websites”. Site access is limited to the sites you approved, one at a time.
2. Read the content security policy (1 minute)
Open the extension’s manifest.json (unzip the package, or browse it from the extension’s details page in developer mode). The extension-pages policy must contain:
connect-src 'none'
That directive tells the browser to refuse every fetch, XHR, WebSocket and beacon from the extension’s pages — whatever the code tries.
3. Search the source for network calls (5 minutes)
The repository ships a check that fails the build if the extension contains network primitives, remote scripts or remote assets, and only allows links to this website:
pnpm install --frozen-lockfile pnpm check-no-network
You can also search by hand for fetch(, XMLHttpRequest, WebSocket and sendBeacon in apps/extension. The extension has no runtime dependencies other than Preact and Preact Signals.
4. Rebuild it and compare hashes (15 minutes)
- Get the source for your version. Clone the repository and check out the tag that matches the version shown in the dashboard’s Verify build page.
- Build the package.
pnpm install --frozen-lockfile pnpm -F extension zip
- Hash it.
shasum -a 256 apps/extension/.output/*.zip
- Compare. The SHA-256 of each release package is published in that release’s notes. If they match, what you run is what is in the source.
Status: the public repository and the first tagged release are not live yet, so release hashes don’t exist yet. This page and the in-extension Verify build page will point to them when they do — until then, checks 1–3 apply to any build you make from source.
Questions
Found something that doesn’t add up? Write to support@pointerapps.net. Security reports are welcome — see security.txt.
Questions
Why can’t I just trust the store listing?+
Cookie extensions have been sold and turned into malware before. A listing can change owner or code overnight, so the checks below are things you can run yourself, on any version.
What if the hash on my machine doesn’t match?+
Don’t install it, and email support@pointerapps.net with the version, your OS and the hash you got. A mismatch can be as simple as a different Node or pnpm version, but it is always worth a look.