Skip to content

Repository files navigation

🧩 ClickPhantom

A powerful, modern, and privacy-focused browser extension that restores full right-click functionality on websites that disable or restrict it. Built for Chromium-based browsers (Chrome, Edge, Brave, Opera) using Manifest V3.


🚀 Features

  • 🔓 Right-Click Restore — Bypass JavaScript context menu blocking on any site.
  • 📝 Text Selection Unlock — Re-enable text selection where it has been artificially disabled.
  • 📋 Copy / Paste / Cut — Remove restrictions on clipboard operations.
  • 🖱 Drag & Drop — Re-enable drag-and-drop functionality where blocked.
  • ⌨ Keyboard Shortcuts — Optionally unblock keyboard shortcuts including developer tools (F12, Ctrl+Shift+I/J/C).
  • 🧠 Smart Detection — Automatically detects and neutralizes event blocking techniques (preventDefault, stopPropagation, stopImmediatePropagation, returnValue).
  • 🌍 SPA & Shadow DOM Support — Handles dynamic single-page applications, shadow DOM, and iframes gracefully.
  • 🛡 Privacy First — Zero tracking, zero analytics, zero network calls. Works entirely offline.
  • ⚙ Granular Control — Per-tab toggle, auto-unblock, domain whitelist/blacklist, and full/partial unlock modes.

💾 Installation

From Source (Developer Mode)

  1. Download and extract clickphantom.zip.
  2. Open your browser and navigate to the extensions page:
    • Chrome: chrome://extensions
    • Edge: edge://extensions
    • Brave: brave://extensions
    • Opera: opera://extensions
  3. Enable Developer mode (toggle in the top-right corner).
  4. Click Load unpacked.
  5. Select the extracted clickphantom folder.
  6. The 🧩 icon will appear in your toolbar.

Tip: To use ClickPhantom on local file:// pages, enable "Allow access to file URLs" in the extension details page.


💡 Usage

Popup Toggle

Click the 🧩 icon in your toolbar to open the popup:

  • 🔓 Enable Unblock — Restores right-click, selection, copy, and drag on the current tab.
  • 🔒 Disable Unblock — Returns the site to its default restricted state.

The popup shows the current domain and whether unblocking is active.

Settings

Click ⚙ Settings in the popup or right-click the icon and choose Options.

Setting Description
Auto-unblock on all sites Automatically enable unblocking everywhere. Use the blacklist to exclude domains.
Full interaction unlock Extends protection to keyboard shortcuts, drag-and-drop, and other blocked interactions.
Whitelist When auto-unblock is OFF, only these domains will be unblocked.
Blacklist When auto-unblock is ON, these domains will never be unblocked.

Context Menu

Right-click anywhere on a page and select Toggle ClickPhantom to quickly enable/disable without opening the popup.


🔧 Technical Architecture

Component Responsibility
manifest.json Manifest V3 declaration, permissions, host matches, and resource mapping.
background.js Service worker managing per-tab state, settings persistence, icon updates, and context menu.
content.js Isolated-world content script that injects inject.js into the main world and bridges settings.
inject.js Main-world script that intercepts and neutralizes blocking event listeners, clears on* handlers, and injects enabling CSS.
popup.html/css/js Minimal emoji-based UI for per-tab toggle and status display.
settings.html/css/js Full settings panel for global preferences and domain rules.

How It Works

  1. Early Injection — content.js runs at document_start and injects inject.js into the page's main JavaScript world before site scripts execute.
  2. Event Interception — inject.js overrides Event.prototype.preventDefault, stopPropagation, and stopImmediatePropagation for protected events (contextmenu, selectstart, dragstart, copy, etc.), making blocking attempts ineffective.
  3. Listener Wrapping — addEventListener and removeEventListener are wrapped to ensure compatibility while preserving our protections.
  4. Property Cleanup — Periodic cleanup of oncontextmenu, onselectstart, and similar inline handlers.
  5. CSS Injection — Injected styles force user-select: auto, pointer-events: auto, and -webkit-touch-callout: default across the page and inside shadow DOM.
  6. State Management — The service worker maintains tab states and settings, broadcasting updates to all content scripts.

🛡 Privacy & Security

  • No external network requests — The extension contains no analytics, tracking, or remote configuration.
  • No data collection — All settings and tab states are stored using the browser's native Storage API (chrome.storage.sync / chrome.storage.local).
  • Minimal permissions — Only requests storage, tabs, and contextMenus plus host access to inject content scripts.
  • Open source — Fully auditable codebase with no obfuscated or minified logic.

📘 File Structure

clickphantom/
├── manifest.json
├── background.js
├── content.js
├── inject.js
├── popup.html
├── popup.css
├── popup.js
├── settings.html
├── settings.css
├── settings.js
├── icons/
│   ├── icon16.png
│   ├── icon32.png
│   ├── icon48.png
│   ├── icon128.png
│   ├── icon16-gray.png
│   └── icon32-gray.png
├── README.md
├── LICENSE
└── .gitignore

📌 License

MIT License — see LICENSE for details.


🤝 Contributing

Contributions are welcome. Please ensure your changes maintain the extension's privacy-first, zero-network philosophy. Test against popular sites with aggressive blocking before submitting.


ClickPhantom — Take back control of your browser.

About

A powerful, modern, and privacy-focused browser extension that restores full right-click functionality on websites that disable or restrict it. Built for Chromium-based browsers (Chrome, Edge, Brave, Opera) using Manifest V3.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Contributors

Languages