Chrome Extension Security Checklist — Developer Guide

4 min read

Chrome Extension Security Checklist

Use this checklist when developing, auditing, or reviewing a Chrome extension.

Input Validation

XSS Prevention

Content Security Policy (CSP)

Permission Minimization

Secure Storage

Communication Security

Network Security

Content Script Isolation

Third-Party Dependencies

Code Review Checklist

Update Security

Supply Chain Security

Quick Reference

| Category | Key Action | |———-|————| | XSS | Use textContent, not innerHTML | | CSP | No unsafe-eval, no unsafe-inline | | Permissions | Request minimum required | | Storage | Use chrome.storage, not localStorage | | Messaging | Validate sender and message schema | | Dependencies | Audit regularly, lock versions |

Part of the Chrome Extension Guide by theluckystrike. Built at zovo.one.