Chrome extension · v0.8.2

Site Operator Check

See who runs this site before you type.

A Chrome extension that shows what a page states about its own operator — with the evidence — the moment you press the toolbar icon.

Available on the Chrome Web Store
example.com/checkout/delivery
A Site Operator Check panel open beside a delivery-address form. Under “This page states who operates it” are the stated company name and address, and the site name as a hint.

USE CASES

Who runs this, before you type

It makes no safety judgement. It lines up what the page states about itself, with the evidence for each line.

Before typing an address or card details into a new shop

You tend to go looking for the operator only once you are at the checkout, then scroll all the way back to the footer. One press of the toolbar icon lines up the company name, address and contact details, quoted from wherever they were found.

Checking whether a site says who runs it, before you sign up

What is not written cannot be found by looking harder, and you rarely know when to stop looking. Each line is marked Stated, Hint or Not confirmed, so the absence itself becomes something you can weigh.

Checking the governing law behind an overseas service

These are the lines you reach only by reading the terms to the end. Governing law, jurisdiction and country are shown as separate rows, and when the page itself is the terms or the policy, its body is read too.

Assessing a service you might use at work

Where what you type is submitted, and which third parties the page pulls in, are not visible from the design. Data storage, transfer destination, where input is sent, and the other origins being loaded are each shown as their own row.

Features

It shows. It does not judge.

What this page says, and what it leaves unsaid. That is where it stops — the judgement stays with you. No score, no stars, no red-or-green verdict.

Never reads what you type

It never touches a field’s value, files, the selection or the clipboard.

No network

No networking API exists anywhere in the shipped code.

No safety verdict

There is no score, no trust rating, no star rating and no traffic-light colour.

Always with evidence

You can see where each statement was found, quoted in place.

WHAT IT SHOWS

What it shows, and how far it goes

It gathers only what the page states, and separates it by how firmly it was said.

1Three levels of certainty

Stated

Claimed as the operator

Found where a site names its own operator: a legal notice, structured data, terms.

Hint

Reads that way, but is not a claim

A company name in the footer, a site name in meta — operator-like, but not a statement.

Not confirmed

Not stated on this page

What was not found is not hidden either. Finding nothing does not mean a site is safe.

The panel with “Show details and evidence” expanded: under the Evidence heading are the places each statement was found, with excerpts.
Open the evidence and you get where each line was found, quoted in place.
The panel on a campaign sign-up page, headed “The operator could not be determined from this page”, listing what was not confirmed.
On a page that states no operator, it says plainly what it could not confirm.
The panel on a sign-up form: the company name and address lines each carry an “Other page” badge.
Read the site’s legal notice first and the form fills in, marked “Other page”.

2Shown as separate lines

Nothing is merged. When several company names appear, all of them are listed rather than reconciled into one.

Company name Address and contact Country or region Governing law Jurisdiction Data storage location Data transfer destination Where the form submits Origins the page loads

3How far it goes

A limited reading range

Footers, address elements, structured data, meta tags, link text and URLs, and the sources of embedded frames and scripts. The page body is read only when the page itself is a legal notice, terms, privacy policy or company page. Articles, blog posts, product copy and user posts are never read.

This page

Evidence, quoted in place

Where it was found and what it said — up to three excerpts per value.

Always

Fills in from the site’s own pages

If you visited this site’s legal notice, terms, privacy policy or company page earlier in this session, what was found there is added, marked “Other page”. It never follows a link on its own.

This session

Related pages as links

Up to six candidates — company profile, statutory notice, terms, privacy policy — listed as links. It never opens them for you.

You open them

Shows the other origins the page loads

It lists where the embedded frames and scripts on the page are served from. Providers it can name from the bundled list (about 120) are labelled and collapsed by default, and the count is always shown. Where the site itself mentions that domain, the sentence is quoted too. Collapsing does not mean safe, and no judgement is made either way.

Bundled list

Interface language

Follows the browser language. Japanese and English are supported.

日本語 English
Automatic

What a page loads is what it loads — not necessarily where your input goes. Even when a third-party payment button says nothing in the markup about where it leads, the fact that something is served from elsewhere can still be seen.

HOW IT WORKS

Only when you press it

It watches nothing on the page. In exchange for never appearing on its own, it can be run as often as you like — and neither running it nor closing it is recorded anywhere.

1

Run it from the icon

Press the toolbar icon, then “Check who runs this page”, and a panel appears in the corner of the screen. Press it while you are typing and it steals neither the click nor the focus.

The toolbar icon Check who runs this page A panel in the corner Keep typing
2

Gathers what the page states

It collects the operator statements and sorts them into stated, hint and not confirmed. Several company names stay several company names. The other origins the page loads are picked up at the same time.

Legal notice Structured data Footer and address Meta and links
3

Read it, close it

When you are done, you close it. Esc works too while focus is inside the panel. There is nothing to approve, and no record that you looked.

Close Esc also closes it

Open it again on the same page and it remembers nothing from last time. It reads the page as it is, every time.

GET STARTED

Install and use

Add it, and press the icon when you want to know. There is no settings screen.

The Site Operator Check listing on the Chrome Web Store

1Install

Just press “Add to Chrome” on the Chrome Web Store.

The pinned Site Operator Check icon in the toolbar, with the popup showing the “Check this page’s operator” button

2Pin it to the toolbar

Open the extensions icon (the puzzle piece) at the top right of Chrome and turn on the pin for Site Operator Check to reach it in one click.

A contact form page showing the toolbar popup and, below it, the operator panel it opened in the corner of the screen

3Check from the icon

Press the icon, then “Check who runs this page”, and a panel appears in the corner. The cursor stays in the field, so you can carry on typing.

The panel with the “Show details and evidence” link visible, the operator, address and country each on their own line

4Show details and evidence

Open “Show details and evidence” in the panel for the excerpts, what could not be confirmed, the other origins the page loads, and the related-page candidates.

It does not run on chrome:// pages, the Chrome Web Store, the PDF viewer, local files or view-source pages, because Chrome does not allow it.

PRIVACY

The privacy promise

A tool for checking who you are dealing with has no business collecting anything about you.

It does not read what you are about to type.

Never touching a value, a file, the selection or the clipboard is not a promise in a comment — it is checked mechanically at build time.

What is kept

One thing: the operator information read from this site’s own legal notice, terms, privacy policy or company page (per origin, at most 30 origins, at most 64KB each). It disappears when the browser restarts. What you do is never stored — an extension that verifies nothing has no state amounting to “approved”, so there is nothing to record.

Network

None. No networking API exists in the shipped code, and the extension pages declare connect-src 'none'. There are no analytics, no ads and no third-party SDKs.

Permissions

Only “storage”. No host permissions are declared. Browsing history, cookies, bookmarks and downloads are never touched.

Check it yourself

The extension’s own traffic (the service worker) is visible in the dedicated DevTools opened from chrome://extensions; the content script’s traffic is visible in the page’s DevTools (F12).

Read the privacy policy →How to verify it (transparency) →

Frequently asked questions

Does it read what I type?

No. It never accesses a value, files, the selection or the clipboard. A build-time check confirms mechanically that none of those appear in the code that handles fields.

Will it tell me whether a site is safe?

No. It makes no safety judgement. It tells you what the page states and what it does not. It does not prove that a company exists, and it does not verify that the statements are correct. Finding nothing does not mean a site is safe.

Does it fetch the pages it links to?

No. It reads only the page you have open. Something is shown as “Other page” solely because you yourself visited that site’s legal notice, terms, privacy policy or company page earlier in this session.

Does it appear on its own?

No. It appears only when you press the toolbar icon. It subscribes to nothing on the page — no clicks, no Tab, no focus changes — so nothing the page does can bring it up. Run it as often as you like; neither running it nor closing it is stored.

LIMITS

What it can and cannot do

It is not a tool that reliably stops every disclosure before it happens. Here is the line, drawn in advance.

Aspect It can It cannot
The operatorShow the operator information stated on the page, with evidenceProve that the company exists
The statementsShow where each statement was found and what it saidVerify that the statements are correct
OwnershipList every company name found, without merging themFully identify parent companies, subsidiaries or ownership
Submission targetShow the destination declared in the markup (a form’s action, a submit button’s formaction)Know a destination that JavaScript decides at submit time. The other origins it lists are what the page loads, which is not the same as where your input goes
Stepping inCheck, there and then, when you press the iconWatch your typing, appear on its own, warn you, or stop a submission — it subscribes to nothing on the page
Its placeGive you more to go onReplace a security product, legal advice, or your own decision to transact

Finding no information does not mean a site is safe. Finding it all set out properly does not mean the transaction is fine either. The decision stays with you.

See the permissions and network table →

See who runs this site before you type.

Free, entirely local, no network. Add it to Chrome and start using it today.

View on Chrome Web Store

LEGAL

Before you use it

The privacy promise and the rules of use are set out in the documents below.