1. Permissions — only what you use
- Remove any permission no shipped feature calls. If you can't point to the line of code, drop it.
- Replace broad
<all_urls>host access with specific match patterns, oractiveTab+scripting. - In the listing, justify each remaining permission in one line.
2. Single purpose — one clear job
- State the purpose in one sentence. If you need "and also…", split into two extensions.
- Every permission and UI element should serve that one purpose.
3. Remote code — bundle everything (MV3)
- No
eval, nonew Function, no external<script src>. - CSP set to
script-src 'self'. Fetch data, never code.
4. Privacy — policy = disclosure = code
- Public privacy policy URL that matches what your code actually does.
- Fill the data-use disclosure honestly; if it's all local, make sure no network call contradicts "no data collected".
5. Metadata — no spam, no trademarks
- Describe real functionality; no keyword stuffing.
- Don't use another brand as your title's trademark. Screenshots must match the actual UI.
6. Functionality — works in 60 seconds
- Core feature reachable without login/paywall (guest mode or reviewer test notes).
- Zero console errors on a clean install. Deliver real value, not a thin wrapper.
Check your manifest before you submit
Paste your manifest.json and get per-permission risk flags in seconds — free. Or paste a rejection you already got.