A powerful, modern, and privacy-focused browser extension that restores full right-click functionality on websites that disable or restrict it. Built for Chromium-based browsers (Chrome, Edge, Brave, Opera) using Manifest V3.
- 🔓 Right-Click Restore — Bypass JavaScript context menu blocking on any site.
- 📝 Text Selection Unlock — Re-enable text selection where it has been artificially disabled.
- 📋 Copy / Paste / Cut — Remove restrictions on clipboard operations.
- 🖱 Drag & Drop — Re-enable drag-and-drop functionality where blocked.
- ⌨ Keyboard Shortcuts — Optionally unblock keyboard shortcuts including developer tools (F12, Ctrl+Shift+I/J/C).
- 🧠 Smart Detection — Automatically detects and neutralizes event blocking techniques (
preventDefault,stopPropagation,stopImmediatePropagation,returnValue). - 🌍 SPA & Shadow DOM Support — Handles dynamic single-page applications, shadow DOM, and iframes gracefully.
- 🛡 Privacy First — Zero tracking, zero analytics, zero network calls. Works entirely offline.
- ⚙ Granular Control — Per-tab toggle, auto-unblock, domain whitelist/blacklist, and full/partial unlock modes.
- Download and extract
clickphantom.zip. - Open your browser and navigate to the extensions page:
- Chrome:
chrome://extensions - Edge:
edge://extensions - Brave:
brave://extensions - Opera:
opera://extensions
- Chrome:
- Enable Developer mode (toggle in the top-right corner).
- Click Load unpacked.
- Select the extracted
clickphantomfolder. - The 🧩 icon will appear in your toolbar.
Tip: To use ClickPhantom on local
file://pages, enable "Allow access to file URLs" in the extension details page.
Click the 🧩 icon in your toolbar to open the popup:
- 🔓 Enable Unblock — Restores right-click, selection, copy, and drag on the current tab.
- 🔒 Disable Unblock — Returns the site to its default restricted state.
The popup shows the current domain and whether unblocking is active.
Click ⚙ Settings in the popup or right-click the icon and choose Options.
| Setting | Description |
|---|---|
| Auto-unblock on all sites | Automatically enable unblocking everywhere. Use the blacklist to exclude domains. |
| Full interaction unlock | Extends protection to keyboard shortcuts, drag-and-drop, and other blocked interactions. |
| Whitelist | When auto-unblock is OFF, only these domains will be unblocked. |
| Blacklist | When auto-unblock is ON, these domains will never be unblocked. |
Right-click anywhere on a page and select Toggle ClickPhantom to quickly enable/disable without opening the popup.
| Component | Responsibility |
|---|---|
manifest.json |
Manifest V3 declaration, permissions, host matches, and resource mapping. |
background.js |
Service worker managing per-tab state, settings persistence, icon updates, and context menu. |
content.js |
Isolated-world content script that injects inject.js into the main world and bridges settings. |
inject.js |
Main-world script that intercepts and neutralizes blocking event listeners, clears on* handlers, and injects enabling CSS. |
popup.html/css/js |
Minimal emoji-based UI for per-tab toggle and status display. |
settings.html/css/js |
Full settings panel for global preferences and domain rules. |
- Early Injection —
content.jsruns atdocument_startand injectsinject.jsinto the page's main JavaScript world before site scripts execute. - Event Interception —
inject.jsoverridesEvent.prototype.preventDefault,stopPropagation, andstopImmediatePropagationfor protected events (contextmenu, selectstart, dragstart, copy, etc.), making blocking attempts ineffective. - Listener Wrapping —
addEventListenerandremoveEventListenerare wrapped to ensure compatibility while preserving our protections. - Property Cleanup — Periodic cleanup of
oncontextmenu,onselectstart, and similar inline handlers. - CSS Injection — Injected styles force
user-select: auto,pointer-events: auto, and-webkit-touch-callout: defaultacross the page and inside shadow DOM. - State Management — The service worker maintains tab states and settings, broadcasting updates to all content scripts.
- No external network requests — The extension contains no analytics, tracking, or remote configuration.
- No data collection — All settings and tab states are stored using the browser's native Storage API (
chrome.storage.sync/chrome.storage.local). - Minimal permissions — Only requests
storage,tabs, andcontextMenusplus host access to inject content scripts. - Open source — Fully auditable codebase with no obfuscated or minified logic.
clickphantom/
├── manifest.json
├── background.js
├── content.js
├── inject.js
├── popup.html
├── popup.css
├── popup.js
├── settings.html
├── settings.css
├── settings.js
├── icons/
│ ├── icon16.png
│ ├── icon32.png
│ ├── icon48.png
│ ├── icon128.png
│ ├── icon16-gray.png
│ └── icon32-gray.png
├── README.md
├── LICENSE
└── .gitignore
MIT License — see LICENSE for details.
Contributions are welcome. Please ensure your changes maintain the extension's privacy-first, zero-network philosophy. Test against popular sites with aggressive blocking before submitting.
ClickPhantom — Take back control of your browser.