XPI Viewer and Extractor Online
Inspect an extension's identity, entry points and packaged files without installing it.
Open Firefox XPI extensions
The XPI viewer reads WebExtension Manifest V2 and V3 packages. Inspect Firefox identity, background and content scripts, ordinary and optional permissions, host declarations and resources. A declared permission describes requested access; it is not a malware verdict.
example.xpi/ EXTENSION-SUMMARY.txt extension.json files/manifest.json files/background.js files/icons/icon.svg
Legacy non-WebExtension XPI packages are explicitly labeled. Their install.rdf, chrome.manifest and bootstrap.js remain available as data; the viewer does not invent a modern manifest or permission model. Unsupported legacy metadata receives diagnostic notes.
Browse and download extension files
Processing runs on our servers. Start with EXTENSION-SUMMARY.txt and extension.json, then open original files under files/. Relative paths remain navigable. Download individual members or the complete result ZIP. Recovered C# is kept under recovered/ with assembly provenance in the report.
Uploaded HTML, JavaScript and SVG follow the site's inert text or isolated image preview boundaries. Extensions, hooks, npm scripts and native hosts are never installed or executed. Dependencies and referenced URLs are not downloaded. Signature verification is not performed.
Limits and source recovery
Bundled JavaScript and source maps are preserved as supplied. Original TypeScript, names and comments are not reconstructed, and formatting minified code is not original-source recovery. See source-map recovery work for that separate feature. Native, Hermes, V8 and custom bytecode do not pass through a generic JavaScript decoder.
Metadata reads are limited to 1 MiB per manifest or CRX header. ZIP64 and split ZIPs are unsupported. Extraction shares the existing five-minute parent budget, 1 GiB expanded data, 256 MiB per file, 25,000 entries and four nested layers; worker limits may stop processing earlier. Each assembly recovery gets up to 30 seconds within that budget. Complete extracted files remain available after a failure; check DECOMPILATION-NOTES.txt for details.
Related viewers: CRX, XPI, VSIX, Electron ASAR and packaged JavaScript, .NET DLL decompiler and NuGet package viewer.