What "remote code" actually means
Under MV3, all executable code must ship inside the extension package. Fetching data is fine; fetching code and running it is not. Reviewers flag anything that could execute JavaScript loaded from outside the package.
eval()ornew Function("…")anywhere in your code (or a bundled library that uses them).- An external
<script src="https://…">— loading JS from a CDN or your own server at runtime. - Injecting a remote script tag into the page from a content script.
- A CSP that allows
unsafe-evalor non-selfscript sources.
How to fix it and resubmit
- Bundle everything. Ship all JavaScript inside the package. Replace CDN
<script>tags with local files. - Remove eval. Delete
eval/new Function; if a library needs them, switch to a build that doesn't (many libraries offer a CSP-safe build). - Lock the CSP. Set
content_security_policytoscript-src 'self'— nounsafe-eval, no remote origins. - Fetch data, not code. Talk to your server with
fetchfor JSON/config; never download and execute scripts.
Rule of thumb: if any JavaScript that runs isn't a file inside your .zip, it will be flagged.
Remote code is one of six rejection families (permissions/Purple Potassium, metadata/Blue Argon, single purpose, privacy, remote code, functionality/Yellow Magnesium). If your email lists more than one, fix them together — a second rejection resets the review clock.
Not sure which script got flagged?
Paste your rejection email or manifest — get the exact cause in seconds, free. Or we fix it and resubmit for you.
Free diagnosis → Functionality rejection? →