

Chrome Extension
The Sonatype extension for Chromium browsers helps developers identify open source risks and policy violations in real time — right from Google Chrome or Microsoft Edge. Connect the Chrome extension to your Sonatype Platform to scan components as you browse public open source registries like Maven Central, npm, PyPI, and more.
Works With: 
Chrome + Sonatype Platform
This extension connects directly to your Sonatype Platform instance, giving developers the information they need to make secure choices at the point of discovery. Whether browsing Java, JavaScript, or Python packages, the extension enforces your organization’s open source policies and shifts security left — before code ever enters the build.
Explore how Sonatype’s browser extension integrates seamlessly with Chrome and Microsoft Edge to deliver real-time component intelligence. Gain visibility into vulnerabilities and policy violations without leaving the registry page.
Chrome Extension Features
Instant Risk Visibility in Your Browser
Creates a view of known vulnerabilities, license issues, and component metadata as you browse package pages on public repositories — no context switching required.
Enforces Sonatype Platform Policies
Applies your organization’s security and license policies directly within the browser using Sonatype Platform intelligence, with clear pass/fail indicators and guidance.
Lightweight, Cross-Browser Support
Works seamlessly in both Chrome and Microsoft Edge, delivering fast, unobtrusive insights designed for developers and security-conscious teams.
Powered by Sonatype Intelligence
Backed by Sonatype’s industry-leading data, the extension provides deep, curated insights that go beyond public CVE feeds to ensure smarter component decisions.
Related Integrations
Integration Resources
Chrome Extension FAQs
Is the Sonatype Chrome extension free to use?
Yes, the extension is free to install. To access full functionality and receive policy-driven insights, it must be connected to an instance of the Sonatype Platform.
Where can I use the Sonatype extension?
The extension can be used in both Google Chrome and Microsoft Edge. It enhances your experience when browsing popular open source registries like npm and Maven Central.
What do I need to configure after installation?
After installing the extension, you will need to connect it to your Sonatype Platform instance by entering your IQ Server URL and access token. Configuration details are provided in the extension’s settings panel.
What does the extension evaluate?