jshelter.org appears to be based almost entirely around client-side checks injected into web sites. It's not clear how it's meant to work and avoid being bypassed. There should be prominent documentation explaining what makes their use of client-side checks different.
Conversation
Replying to
They give users the impression that it's some kind of sandboxing or enforced restrictions. Instead, it primarily appears to be based on injecting code into the web site intercepting calls. An extension isn't the proper way to implement these things in a way that's enforced.
2
