3 items
Scans your installed Chrome extensions and ranks them by risk. Most people install a browser extension once, click "Add extension" on a permission dialog they do not read, and never look at it again. Years later the same extension is still there, still able to read every page you open, and it has changed hands twice since you installed it. Nothing in Chrome tells you this, because nothing in Chrome is asking. Engarde asks. It reads what Chrome already knows about every extension you have installed and turns it into one number per extension, with the reasons written out underneath, so you can look at your own browser for thirty seconds and know which of the things inside it can see the most. WHAT YOU GET WHEN YOU OPEN IT A list, worst first. Each row is one extension: its own icon, a score from 0 to 100, and the reasons behind that score written as capabilities rather than API names. Not "webRequest" but "Can observe your network requests". Not "<all_urls>" but "Can read and change data on every website you visit". If you would not knowingly grant that to a coupon finder, the row tells you so without you having to know what a host permission is. Under each row: Disable, Remove, Ignore, Details. Disable and Remove act immediately — Remove hands you Chrome's own confirmation dialog, because uninstalling something on your behalf without asking is not a thing a security tool should do. Details opens that extension's page in Chrome's own settings, where you can see the publisher and the version. WHAT THE SCORE MEANS The score is a weighted sum of capabilities, not a verdict about intent. Three things go into it. The permissions it holds. Some are structurally dangerous and weigh heavily: the debugger permission, which lets an extension attach to any tab and read or rewrite everything in it; native messaging, which lets it talk to programs installed on your computer; proxy, which lets it route your traffic. Others are common and weigh less: seeing your tab titles, managing downloads. Reading and writing cookies sits in between, and matters more than most people think, because a session cookie is a signed-in you. How much of the web it can touch. An extension with access to every site you visit scores heavily for that alone. One scoped to a single domain barely registers. This is usually the single biggest difference between two extensions that look identical in the store. Where it came from. An extension installed from the Chrome Web Store has been through review. One that was sideloaded onto your machine by another program has not, and it is worth knowing which is which. Same for an extension that updates from somewhere other than Google's update service, and for one your organisation force-installed by policy and you cannot switch off. Above 60 is high, 30 to 60 is medium, anything above zero is low, and zero is clean. Those bands are a reading aid, not a judgement. A password manager scores high because a password manager genuinely needs deep access. The question the score helps you ask is whether this particular extension needs what it holds. THREE VIEWS Live is the list described above: everything being watched, worst first. By permission inverts it. One row per capability, heaviest first, and under each one the extensions that hold it. This is the view that answers the question you actually have — "what in here can read my cookies?" — in one glance instead of five. It is also how you notice that the capability you are uneasy about is held by four things when you assumed it was held by one. Ignored is for the ones you have already thought about. A password manager needs deep access. Your company's SSO extension is not going anywhere. Press Ignore and it leaves the Live list, drops out of the by-permission view, and stops counting toward the toolbar badge. It is not hidden and not forgotten — it sits in the Ignored tab with its score intact, and Watch again puts it back. The point is that the warnings you have accepted stop competing for attention with the ones you have not, which is the failure mode of every security tool that cannot be told "yes, I know". THE BADGE The toolbar icon carries a count of enabled, high-risk, non-ignored extensions. Usually that is a blank icon, which is the point: it changes when something changes. Install something that wants everything, and the badge tells you before you have forgotten you installed it. NOTHING LEAVES YOUR BROWSER There is no account, no sign-in, no server and no network call anywhere in this extension. Not telemetry, not an error reporter, not a "check for updates" ping. The code makes no outbound request at all, which is a thing you can verify yourself: open Chrome's DevTools Network tab on the popup and watch it stay empty. The only thing it stores is the list of extension IDs you pressed Ignore on, kept in Chrome's local storage on this profile. That is what Ignore has to remember to work. It is not synced anywhere by us. Engarde reads data about the extensions you have installed. It does not read your browsing history, your tabs, your cookies or the contents of any page — it holds no permission that would let it, which is checkable against the permission list on this page. WHAT IT CANNOT DO Chrome does not let one extension read another extension's code. No extension can, including this one. So Engarde judges declared capability and provenance, not behaviour: it can tell you that an extension is able to read every page you visit, and it cannot tell you whether it does. An extension that asks for little and misuses it will score low here. Treat the score as the first question, not the last word. It is also not a malware scanner. There is no blocklist, no reputation feed, no vendor verdict. It is an inventory of capability, computed on your machine from what Chrome reports. WHO IT IS FOR Anyone who has accumulated extensions for years and has never once audited them, which is nearly everyone. It takes one look to find the two or three that have far more access than they need. It is also useful before you install something: add it, open Engarde, and see what it actually asked for, in words, next to everything else you already trust. Engarde is a security product by Little Omega. This extension is the part of it that runs entirely on your own machine.
Sep 18, 2026
rating_count is the Chrome Web Store ratings count, not a written-review count.
Media assets
Screenshots and videos on the listing.
Has promo video
Whether the listing includes at least one video.
Languages
Declared language locales.
Developer website
Listing exposes a developer website URL.
Contact email
Listing exposes a contact email.
Keyword in name
Case-insensitive substring match in the name.
Keyword in description
Case-insensitive substring match in the description.
Keyword occurrences in description
Count of case-insensitive occurrences in the description.
Category user-count percentile
Share of same-category extensions with fewer users (null if unknown).
These are transparent listing completeness / keyword signals, not a prediction of Chrome Web Store search ranking.