All articles Bot detection

Detecting Browser Automation Run Through Extensions

Extension-based automation is the sophisticated operator’s answer to CDP detection: instead of driving Chrome from outside over the DevTools Protocol, they install a content-script extension that automates the page from inside a real, human-launched browser. There is no controller to detect, which defeats an entire category of tooling, and the injected scripts and synthetic events they rely on leave a different, still-detectable trail.

Why extensions dodge CDP detection

CDP-based detection works because Puppeteer, Playwright, and Selenium attach an external controller with a measurable protocol signature. An extension has no such controller. It runs as a content script in a genuine Chrome the user launched normally, so the CDP artifacts, execution-context timing, Runtime quirks, target structure, simply are not there. For operators burned by CDP scoring, this is the appeal.

What extension automation leaves behind

The tradeoff is that content scripts manipulate the page in ways that differ from a human driving the UI:

  1. Injected script presence. Content scripts run in an isolated world but still touch the DOM. Mutation patterns, unexpected event listeners, and the timing of DOM changes can reveal an automating script.
  2. Synthetic events. Events dispatched programmatically carry different properties than genuine hardware-generated ones: isTrusted is false for script-dispatched events, and coordinate, timing, and target details differ from real input.
  3. Superhuman timing. Extension bots read the DOM directly and act the instant an element appears, with no human perception-and-decision delay, producing action latencies below what a person can achieve.
  4. DOM-access patterns. Reading form fields and buttons through selectors, in a fixed order, at machine speed, contrasts with the scattered, corrective interaction of a human.

The isTrusted anchor

A particularly durable signal is event.isTrusted. The browser sets it to true only for events generated by genuine user interaction and false for events created in script. Extension automation that dispatches synthetic clicks and keystrokes produces untrusted events. A well-designed detector correlates trusted-event ratios with the actions that supposedly caused state changes, so a form that submits with no trusted input preceding it is a strong tell. Because this lives in the interaction layer rather than the environment, it complements the environment-focused checks in our bot-detection signals.

Behavior and identity

Even a careful extension bot has to act, and behavior betrays it:

  • Cadence. Keystroke dwell and flight times, scroll physics, and inter-action pauses stay machine-regular.
  • Perfection. No overshoot, no mis-click, no re-read. Humans are noisy; scripts are not.
  • Cross-session identity. Extension farms still run off a limited set of machines and profiles. A stable visitorId ties the sessions together across storage clears and IP rotation, and the reputation network flags a signature seen abusing one site on the next.

The tradeoff operators are making

Extension automation is a deliberate exchange: give up the power and reliability of CDP-based tooling to gain invisibility from controller detection. That exchange is not free. Content-script automation is more fragile, has to work within extension API limits, and cannot inject or intercept with the precision Puppeteer offers, so building and maintaining it costs more engineering effort than dropping in a stealth plugin. Operators only make this trade when CDP detection has already cost them, which tells you the defense is working even before you catch the extension. And the escape is partial. The whole reason to run inside a real human-launched browser is to look human, yet the automation still has to interact through scripts, and scripted interaction produces untrusted events and superhuman timing that a real human never generates. So the operator pays more to move the fight from the environment layer, where they were losing, to the behavioral layer, where the most human-specific signals live and where they lose again.

A detection recipe

  1. Score the trusted-event ratio against state-changing actions.
  2. Watch DOM mutation and listener patterns for injected-script signatures.
  3. Measure action latency for superhuman reaction times.
  4. Profile input cadence and precision for machine regularity.
  5. Correlate the visitorId across sessions.
  6. Return reason codes so reviewers see the behavioral evidence.

The strategic point

Extension automation is a genuine step up because it removes the controller CDP detection depends on. But it cannot remove the fact that a script, not a human, is doing the interacting, and interaction leaves the most human-specific signals of all. Shifting detection weight from environment to behavior and identity is exactly what neutralizes this class of bot.

Curious how an extension-driven session scores on behavioral signals? Test it in the playground, free to start.

Try it free

Prynt is device intelligence with a free tier — visitor IDs, bot & fraud Smart Signals, and behavioral biometrics, powered by a cross-site network. Start free.

Keep reading