OPSWAT File Security for Browser is a Chrome and Edge extension that can pause a download while MetaDefender checks the URL or file. Depending on configuration and service access, the workflow can combine reputation lookup, multiscanning, Deep Content Disarm and Reconstruction, and sandbox analysis.
This review uses OPSWAT’s current documentation and extension listing as of August 30, 2026. It does not claim that Top5soft tested malware samples, measured scan speed, or verified a detection rate.
Correction published August 30, 2026: The previous edition claimed 9/10 malware detection, scan times from under two seconds to twenty seconds, unlimited free use, hash-only uploads, no retention, and no account requirement without a reproducible test or supporting documentation. It also placed generated interfaces in screenshot positions. This edition removes those claims and images and explains the actual cloud-upload and privacy model.
What the extension does
OPSWAT’s current integration documentation describes a browser extension that checks downloads through MetaDefender Cloud or a configured MetaDefender Core server. It is available for Chrome and Edge.
The documented flow is straightforward:
- The user opens a page, starts a download, or right-clicks a link to scan before downloading.
- The extension can check URL reputation and send the file for one or more MetaDefender workflows.
- MetaDefender returns a clean, blocked, or sanitized result.
- The browser can allow the clean download, warn or block, or offer a sanitized version when applicable.
This is a download checkpoint, not complete endpoint protection. It does not monitor every process, USB device, email client, local file, or post-execution behavior on the computer. A desktop security product and operating-system controls still have a different job.
The extension is open source on GitHub, which allows its client code and changes to be inspected. Open source does not independently verify the cloud engines or guarantee that every configuration is secure.
The analysis layers
OPSWAT documents several technologies behind the extension. Availability and behavior can depend on the server, account, API key, workflow, and file type.
Reputation and hash lookup
A known URL or file hash can receive a reputation result without repeating every analysis stage. This can shorten the decision path for previously analyzed content. A reputation match is still dated evidence, not proof that a new or modified file is harmless.
Multiscanning
MetaDefender runs files through multiple anti-malware engines. OPSWAT’s January 2026 product article and integration documentation say 20+ engines, while the current Chrome Web Store listing says over 30. The number can vary by licensing and workflow, so this review does not promise one fixed engine count.
Deep CDR
For supported document types, Deep CDR can create a sanitized version by removing or rebuilding active elements. That is different from declaring the original file clean. Format support and output behavior should be checked for the organization’s document set.
Sandbox analysis
The documented Adaptive Sandbox can dynamically analyze applicable files. A browser extension does not make sandbox results infallible: timeouts, unsupported dependencies, environment checks, and unavailable command infrastructure can still limit observed behavior.
These layers provide defense in depth. They should be read as separate signals and transformations rather than collapsed into one green checkmark.
Privacy and file handling
The old Top5soft article contradicted itself by saying the file was uploaded to the cloud and later saying it never left the computer. OPSWAT’s current documentation resolves that ambiguity: when cloud scanning is used, the extension sends downloaded files to MetaDefender Cloud for analysis. A hash lookup may occur first, but unknown content can require the complete file.
Standard cloud submission and private scanning are different modes. OPSWAT’s private scanning documentation says ordinary submission permits sharing of results with the cybersecurity community and may permit executable sharing with malware-exchange partners. Paid accounts can enable private scanning so files are not stored or shared, although scan results can remain available. Private processing adds result isolation to the submitting API key and keeps the result out of hash lookup.
The browser-extension settings documentation likewise says paid users can use MetaDefender Cloud private scanning. Users can also point the extension at a private MetaDefender Core deployment. That can change where the file is processed, but the server owner still needs retention, access-control, and logging policies.
Do not upload customer documents, credentials, source code, legal material, or personal data until the exact account, API key, server, and sharing mode have been approved. The Chrome Web Store statement that the extension developer does not collect or use data does not erase the MetaDefender service data flow required for scanning.
Browser controls and administration
The extension’s documented settings include:
- automatic download scanning;
- scan-and-download behavior that saves a file only after an acceptable result;
- browser notifications;
- safe URL checks;
- a maximum-size threshold that skips larger files;
- a custom MetaDefender Cloud API key;
- connection to an on-premises MetaDefender Core server;
- domain allowlists;
- optional sanitized-download behavior;
- a local scan-history view.
The local history can show filename, SHA-256 hash, scan source, time, and result. OPSWAT notes that clearing this extension history does not clear cloud or Core records. That distinction matters for incident retention and privacy requests.
For managed environments, OPSWAT documents deployment through Group Policy, SCCM, Intune, and Google Admin Console. Central deployment can reduce configuration drift, but administrators should explicitly set the API key, server, privacy mode, size threshold, allowlist, and failure behavior. A silent skip caused by file size or server failure should not be mistaken for a clean result.
Cost and limits
The extension can be installed from the Chrome Web Store without a purchase, and OPSWAT’s product article describes adding it to Chrome or Edge for free. That does not establish unlimited MetaDefender processing.
The extension uses the same account model as MetaDefender Cloud. If the user is not signed in, OPSWAT says a default API key can be assigned; a custom Cloud API key can also be configured. Scan volume, file size, engines, sandboxing, CDR, private scanning, and API behavior can therefore depend on the available Cloud or Core entitlement.
OPSWAT’s January 2026 article says the extension supports files and applications up to 4 GB. The settings also allow users to skip files above a chosen threshold. MetaDefender service tiers can have their own processing limits, so a team should test its actual account and file types rather than treat 4 GB as a universal promise.
There is no evidence for the old claims of unlimited scans, no feature gating, or no file-size restrictions. Before rollout, check the MetaDefender account’s current license and usage screen, then document what happens when quota, size, timeout, or service availability prevents a scan.
Strengths and limitations
Documented strengths
- Adds a security decision point to Chrome and Edge downloads.
- Can combine reputation, multiscanning, CDR, and sandbox workflows.
- Supports automatic and right-click scan-before-download flows.
- Can connect to MetaDefender Cloud or a private MetaDefender Core server.
- Provides enterprise deployment and policy-management options.
- Offers a sanitized document when the workflow and file type support it.
- Publishes the extension source code.
Important limitations
- Cloud analysis can upload the complete file.
- Private scanning is a paid capability, not the default meaning of “cloud scan.”
- It is not a replacement for endpoint detection, antivirus, browser isolation, or user training.
- Engine count and feature availability vary across current OPSWAT materials and service tiers.
- Large files, unsupported types, quotas, server failures, and timeouts can prevent complete analysis.
- Chrome and Edge support does not provide a documented Firefox or Safari workflow.
- A clean result is a collection of signals, not a guarantee.
The extension is most useful when an organization wants a centrally managed gate for browser downloads and has already defined the MetaDefender processing and privacy policy behind it.
Alternatives
The source-verified file scanner guide compares analysis types before products.
MetaDefender Cloud is the underlying cloud platform and is the better starting point for API, storage, upload-pipeline, DLP, and private-processing requirements beyond a browser.
VirusTotal is useful for broad reputation context and hash lookup. Its normal public workflow also has sharing implications, while licensed private scanning produces a different analysis set.
Dangerzone locally rebuilds supported documents as PDFs. It is a different answer for someone who only needs to read an untrusted document without sending it to a cloud service.
ANY.RUN provides interactive cloud malware analysis. It fits trained analysts who need to interact with a task rather than ordinary browser users who need a managed download gate.
Filescan.io offers another online analysis workflow. Its current privacy terms and limits should be checked independently before upload.
Verdict
OPSWAT File Security for Browser is a focused extension for adding MetaDefender checks to Chrome and Edge downloads. The combination of reputation, multiscanning, CDR, sandboxing, Cloud or Core routing, and administrator controls can be useful in a managed environment.
The decision depends on configuration, not a detection score. A team should know where each file is uploaded, whether standard or private scanning is active, what entitlement controls the workflow, which file types can be sanitized, and what the browser does when analysis is skipped or unavailable.
Best fit: organizations already using MetaDefender Cloud or Core that want centrally managed download scanning in Chromium-based browsers.
Poor fit: users seeking a local-only scanner, full endpoint protection, a guaranteed clean verdict, or an unlimited anonymous service for confidential files.
Frequently asked questions
Is OPSWAT File Security for Browser free?
The extension can be installed without a purchase. Cloud processing limits and private features depend on the MetaDefender account, API key, and license, so “free extension” should not be read as unlimited service.
Does the extension upload the whole file?
It can. The documented cloud workflow uploads the download to MetaDefender Cloud for analysis when reputation alone is insufficient. Do not rely on the old claim that only a hash or small portion is sent.
Are uploaded files private by default?
Do not assume so. OPSWAT distinguishes ordinary submissions from paid private scanning and private processing. Confirm the selected mode before a sensitive download is scanned.
Does it replace antivirus?
No. It protects a browser-download workflow. Endpoint security covers a broader set of files, processes, devices, persistence, and post-execution behavior.
Which browsers are supported?
OPSWAT documents Chrome and Edge. The current materials do not document equivalent Firefox or Safari versions.



