1. What source-available means
An extension that reads Steam profiles should be readable itself. That is the whole reason the code is published: so that anyone who is about to install it can check what it does, what it sends, and where. Pulse is not open source, and the difference is deliberate. Reading and auditing are welcome. Copying, republishing and building something else out of it are not. The full licence is at the bottom of this page.
2. Read the code that is actually running
These are the store builds themselves, not a copy prepared for show. Each file is byte for byte the archive uploaded to the store, so the SHA-256 below is something you can verify rather than take on faith.
SHA-256 fa149f981fbf11d2e77560aa60634ca0382b7f9c39ce8fc504350ac583566dbb
SHA-256 1943fa42f0ffc2746eeea69460a8d755eeb4e76fc5a525ff3eac4b8f76cd3a80
SHA-256 4ff7dbb2cfed9c124cda493f1e63138577c25120386098e606c6c501d89a2b35
A new version reaches the stores a few days after it is packaged, because every store
reviews it first. If the extension in your browser still says 4.2.6, that
is the reason, and here is that build with its own checksum:
Chrome
(a800b643…3c53),
Edge and Opera
(cd937a7b…58cf),
Firefox
(55e010ee…713d).
There is nothing to build and nothing to compile. Unzip the archive and open the files in any
text editor: content.js is everything that happens on a Steam profile,
background.js is every network request the extension can make, and
manifest.json lists the permissions it asks for. If you want to check that your
installed copy matches, Chrome keeps it under chrome://extensions with Developer mode
on, and its files are readable on disk.
Two things worth reading first, because they are the ones people ask about: the extension
holds one permission beyond the hosts it talks to, storage, used
for your own settings, and it contains no analytics, no telemetry and no identifiers. The
privacy policy says the same thing in prose; the code is where you
confirm it.
3. Where the code lives
There is no public repository, and that is a deliberate choice rather than a gap. The archives above are the code, and the SHA-256 sum printed beside each one is what makes them worth more than a repository would be: a repository shows you code you then have to trust matches the built artifact, while a checksum lets you prove it. Hash the file you downloaded, compare it to the line on this page, and the question is settled without taking anyone's word.
The code is kept in a private Git repository, so its history and releases are intact but not browsable. At run time the extension fetches nothing from any code host, and never did apart from one scheduled job that refreshed a price list for the inventory value badge. That job moved to its own server in August and nothing on this page depends on it.
4. Licence
This is the licence the code is published under, in full.
Pulse Source-Available License
Copyright (c) 2026 ahake. All rights reserved.
The source code in this repository is published publicly for transparency
and security auditing. It is NOT open source.
PERMITTED
- Viewing and reading the source code (e.g. to audit what the extension
does before installing it).
- Installing and using the official Pulse extension published by the
author (for example via the Chrome Web Store), free of charge.
NOT PERMITTED without the author's prior written permission
- Redistributing, publishing, mirroring, or sublicensing the code or any
part of it.
- Modifying it or creating derivative works.
- Using the code, in whole or in part, in any other software, product,
or service, commercial or non-commercial.
- Selling the code or any derivative of it.
This license applies to the code as of the date of this file and going
forward. The software is provided "AS IS", without warranty of any kind,
express or implied. The author is not liable for any claim, damages, or
other liability arising from the software or its use.
For licensing or permission requests, ask on Discord.
5. Found something
If you read the code and something looks wrong, say so on Discord. That is the fastest way to reach the person who wrote it, and since there is no public repository to open an issue in, it is also the only way. Security issues are read first and answered first.