OPERATIONS · operating reference

Browser extension safety boundaries

A guide to reviewing a permission-minimal browser companion without confusing local warnings with proof that a page is safe.

Reference center

What this page establishes

Manifest permissions define which browser capabilities an extension may request.

Active-tab access is narrower than persistent access to every site.

A local URL heuristic cannot authenticate a business, contract, or payment destination.

Chrome Extensions API reference

Practical review sequence

1

Inspect manifest.json before loading an unpacked extension.

2

Reject unexpected host permissions or wallet access.

3

Use a separate authoritative source to verify every payment destination.

Download Safety Companion

Recheck primary sources before acting

Contracts, names, issuers, governance, bridges, providers, networks, fees, and access rules can change. CoinPork provides an operating checklist, not financial, legal, tax, accounting, or cybersecurity advice.