+
Click any green + on the left to see a
plain-language explanation here.
Basics
Manifest version
This tells Chrome which rulebook the extension follows. VHelper
uses Manifest V3 — the current standard for
Chrome, Edge, and similar browsers.
Why it matters to you
It is not a permission. It simply means the extension is built
the modern, safer way browsers expect today.
Basics
Default language
Sets English as the fallback language when translating the
extension’s name, description, and menus.
Why it is required
So labels appear correctly even if a translation file is
missing for your language.
Basics
Name & description
The odd-looking
__MSG_…__ values are placeholders. The browser
replaces them with the translated name and description for your
language.
Why it is required
Every extension must declare a public name and short
description for the store listing and your browser’s extension
manager.
Basics
Version 4.7.1
This is the release number of the extension you are looking at.
Stores and browsers use it to know when an update is available.
Why it is required
Without a version number, the browser cannot install or update
the extension safely.
Permissions
API permissions
This list is what Chrome shows when you install VHelper. Each
item unlocks a specific browser feature — not “access to
everything.”
VHelper asks for five capabilities:
alarms, contextMenus,
storage, tabs, and
notifications. Use the
+ next to
each one for details.
Why it is required
Browsers force extensions to declare these up front so you can
see what the extension is allowed to do before you install it.
Permission
alarms
Lets VHelper schedule quiet background check-ins — like a timer
that wakes the extension every so often.
Why VHelper needs it
Used for periodic maintenance tasks (for example health checks
and light analytics timers) without keeping a page open or
draining resources with constant polling.
Permission
contextMenus
Allows VHelper to add items to the right-click menu in your
browser.
Why VHelper needs it
So you can do handy things from the context menu — such as
capturing a bug report — without hunting through settings.
Permission
storage
Lets the extension save your preferences and local data on your
device (settings, filters, UI choices, and similar).
Why VHelper needs it
Without storage, your setup would reset every time you close
the browser. Your choices stay on your machine via the
browser’s extension storage — not in a random website cookie.
Permission
tabs
Lets VHelper talk to browser tabs it is allowed to work with —
for example opening a page or sending a message to a Vine tab.
Why VHelper needs it
Features like the Live Feed, bug reporting, and coordinating
between Vine tabs need a way to find the right tab and pass
messages. It does not grant a free pass to read every site you
visit.
Permission
notifications
Allows VHelper to show desktop notifications from the browser
(the little pop-ups outside the Amazon page).
Why VHelper needs it
So you can be alerted about new finds or important events even
when you are not staring at the Vine grid. You can turn
notification styles down in your OS or extension settings.
Security
Content Security Policy
A strict allow-list of where the extension’s own pages may load
scripts, images, fonts, and network connections from. The value
is one long string in the manifest — scroll horizontally in the
code panel if needed.
-
Scripts only from the extension itself (
'self')
-
Images/fonts from Amazon media hosts and the extension
-
Connections to VHelper APIs, Amazon, and optional notify
services you configure (Discord, Telegram, ntfy, etc.)
Why it is required
It is a safety fence: even if something goes wrong, the
extension pages cannot freely load code from arbitrary
websites.
UI
Icons
Points to the VHelper logo images shown in the toolbar, the
Chrome Web Store, and the extensions list.
Why it is required
So you can recognize VHelper at a glance. Not a privacy
permission.
UI
Toolbar action
Defines what happens when you click the VHelper icon in the
browser toolbar: which popup opens, the tooltip title, and which
icon to show.
Why it is required
This is how you open the main VHelper panel. It does not grant
extra site access by itself.
UI
Options page
Tells the browser which page to open when you choose
“Options” / “Extension options” from the extensions manager.
VHelper reuses the same homepage panel.
Why it is required
So settings are available from the browser’s built-in extension
menu, not only from the toolbar icon.
Site access
Host permissions (Amazon)
This is the big one people notice at install time. It grants
VHelper permission to contact Amazon Vine marketplaces and
Amazon’s media hosts — the sites the extension is built for.
Included patterns cover:
- Amazon product media (
media-amazon.com)
-
Vine marketplaces such as .com, .ca, .co.uk, .de, .fr, .es,
.it, .co.jp, .com.au, .com.br, .com.mx, .sg, and .in
Why the whole domain (not just /vine)?
Host permissions control network access — whether
VHelper may talk to that Amazon site at all. They are not the
same as content scripts, which decide which pages get
VHelper UI injected.
Content scripts already limit on-page changes to
/vine/, review pages, and checkout/thank-you
pages. But several features still contact other paths on the
same Amazon host — notably Order Now’s checkout entry
(/checkout/entry/buynow) and, for the review
tools, an occasional product-page request to look up a title.
Product images also come from
media-amazon.com (listed separately). Restricting
host permission to amazon.com/vine/* would break
those flows, so the permission covers the Amazon host while
page injection stays narrowly scoped.
Optional
Optional host permissions
These are not granted automatically. They only
unlock if you approve them later — typically when you
save a custom webhook URL for notifications.
Built-in providers (like Discord) can work without this prompt.
Custom endpoints need a one-time “Allow” so the browser will let
the extension contact that specific address.
Why it is listed
Webhooks can point anywhere you choose. Listing optional
http(s)://*/* lets Chrome ask you per origin
instead of baking broad access into the install permission
screen.
Resources
Web-accessible resources
Lists extension files (images, CSS, themes, sounds, scripts,
locale strings) that Amazon Vine pages are allowed to load from
the extension.
Why it is required
Modern browsers block webpages from reading extension files
unless they are explicitly listed. This is how Vine pages can
show VHelper icons, styles, and UI without exposing your whole
extension package to the open web.
Architecture
Background service worker
The “always available” brain of the extension. It runs in the
background (when needed) to handle alarms, notifications, tab
messaging, and context menus — even if you close a Vine tab.
Why it is required
Features that must work across tabs or while you are elsewhere
in the browser need a background script. Manifest V3 runs this
as an efficient service worker instead of a permanent hidden
page.
Page scripts
Content scripts
These are small programs the browser injects into matching Amazon
pages. They are what transform the Vine experience — layout,
filters, live feed hooks, review helpers, and more.
VHelper declares several groups, each limited to specific URL
patterns (Vine, reviews, or checkout). Tap the individual
+ buttons
below for each group.
Why it is required
Without content scripts, the extension could not change or
enhance what you see on Amazon Vine pages at all.
Content script
Vine pages (main UI)
Injects VHelper’s stylesheets and the main bootloader on Amazon
Vine URLs (paths like /vine/), after the page
document has loaded.
Why VHelper needs it
This is the core experience: tile layout, hide/sort tools,
themes, monitor UI, and related Vine enhancements.
Content script
Vine pages (early boot)
Runs a tiny bit of code as early as possible on Vine pages
(document_start) so VHelper can prepare before the
page finishes painting.
Why VHelper needs it
Some fixes and setup must happen before Amazon’s own scripts
finish — for example avoiding flicker or race conditions with
the stock Vine UI.
Content script
Review pages
Separate scripts (and light CSS) for Amazon review and
edit-review pages across the same marketplaces.
Why VHelper needs it
Vine members write reviews. These scripts help with review
workflows — including media upload assistance — only on review
URLs, not on every Amazon page.
Content script
Checkout & thank-you pages
A focused script on Amazon checkout and order thank-you URLs
(including frames) to monitor the order flow when relevant.
Why VHelper needs it
So VHelper can notice when you successfully request an item.
It is scoped to checkout/thank-you paths — not your whole
Amazon account area.