Transparency

Source code

Last updated: September 28, 2026

1. What source-available means

An extension that reads Steam profiles should be readable itself. That is the whole reason the code is published: so that anyone who is about to install it can check what it does, what it sends, and where. Pulse is not open source, and the difference is deliberate. Reading and auditing are welcome. Copying, republishing and building something else out of it are not. The full licence is at the bottom of this page.

2. Read the code that is actually running

These are the store builds themselves, not a copy prepared for show. Each file is byte for byte the archive uploaded to the store, so the SHA-256 below is something you can verify rather than take on faith.

Chrome, Edge, Brave and the Steam client
cs2-stats-extension-v4.2.9.zip · 417 KB · version 4.2.9
SHA-256 fa149f981fbf11d2e77560aa60634ca0382b7f9c39ce8fc504350ac583566dbb
Edge and Opera listing build
pulse-edge-opera-v4.2.9.zip · 417 KB · same code, shorter listing name
SHA-256 1943fa42f0ffc2746eeea69460a8d755eeb4e76fc5a525ff3eac4b8f76cd3a80
Firefox
pulse-firefox-v4.2.9.zip · 417 KB · event page instead of a service worker
SHA-256 4ff7dbb2cfed9c124cda493f1e63138577c25120386098e606c6c501d89a2b35

A new version reaches the stores a few days after it is packaged, because every store reviews it first. If the extension in your browser still says 4.2.6, that is the reason, and here is that build with its own checksum: Chrome (a800b643…3c53), Edge and Opera (cd937a7b…58cf), Firefox (55e010ee…713d).

There is nothing to build and nothing to compile. Unzip the archive and open the files in any text editor: content.js is everything that happens on a Steam profile, background.js is every network request the extension can make, and manifest.json lists the permissions it asks for. If you want to check that your installed copy matches, Chrome keeps it under chrome://extensions with Developer mode on, and its files are readable on disk.

Two things worth reading first, because they are the ones people ask about: the extension holds one permission beyond the hosts it talks to, storage, used for your own settings, and it contains no analytics, no telemetry and no identifiers. The privacy policy says the same thing in prose; the code is where you confirm it.

3. Where the code lives

There is no public repository, and that is a deliberate choice rather than a gap. The archives above are the code, and the SHA-256 sum printed beside each one is what makes them worth more than a repository would be: a repository shows you code you then have to trust matches the built artifact, while a checksum lets you prove it. Hash the file you downloaded, compare it to the line on this page, and the question is settled without taking anyone's word.

The code is kept in a private Git repository, so its history and releases are intact but not browsable. At run time the extension fetches nothing from any code host, and never did apart from one scheduled job that refreshed a price list for the inventory value badge. That job moved to its own server in August and nothing on this page depends on it.

4. Licence

This is the licence the code is published under, in full.

Pulse Source-Available License
Copyright (c) 2026 ahake. All rights reserved.

The source code in this repository is published publicly for transparency
and security auditing. It is NOT open source.

PERMITTED
  - Viewing and reading the source code (e.g. to audit what the extension
    does before installing it).
  - Installing and using the official Pulse extension published by the
    author (for example via the Chrome Web Store), free of charge.

NOT PERMITTED without the author's prior written permission
  - Redistributing, publishing, mirroring, or sublicensing the code or any
    part of it.
  - Modifying it or creating derivative works.
  - Using the code, in whole or in part, in any other software, product,
    or service, commercial or non-commercial.
  - Selling the code or any derivative of it.

This license applies to the code as of the date of this file and going
forward. The software is provided "AS IS", without warranty of any kind,
express or implied. The author is not liable for any claim, damages, or
other liability arising from the software or its use.

For licensing or permission requests, ask on Discord.

5. Found something

If you read the code and something looks wrong, say so on Discord. That is the fastest way to reach the person who wrote it, and since there is no public repository to open an issue in, it is also the only way. Security issues are read first and answered first.