Remote code (Manifest V3)

Chrome Web Store remote code rejection — decoded

Manifest V3 bans remotely hosted code. This rejection means your extension runs eval, loads an external script, or otherwise executes JavaScript that isn't in the package. Here's what triggers it and how to get approved.

What "remote code" actually means

Under MV3, all executable code must ship inside the extension package. Fetching data is fine; fetching code and running it is not. Reviewers flag anything that could execute JavaScript loaded from outside the package.

The things that trigger it most:

How to fix it and resubmit

Rule of thumb: if any JavaScript that runs isn't a file inside your .zip, it will be flagged.

Remote code is one of six rejection families (permissions/Purple Potassium, metadata/Blue Argon, single purpose, privacy, remote code, functionality/Yellow Magnesium). If your email lists more than one, fix them together — a second rejection resets the review clock.

Not sure which script got flagged?

Paste your rejection email or manifest — get the exact cause in seconds, free. Or we fix it and resubmit for you.

Free diagnosis → Functionality rejection? →