Is javascript safe?

Clean risk

The javascript extension lets users store custom JavaScript per domain and injects it into every page on that domain on each navigation.

Users write arbitrary JavaScript in the extension popup, which is saved to local storage keyed by hostname. On every page load matching any URL, the content script reads the stored script for that hostname and appends it as a <script> element to the page body. The options page also allows direct editing of the raw storage JSON. No data is sent to external servers.

cheev0.4.0Firefox Add-ons
0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Updated 17 September 2026amo-1002271