Mastering Content Script Injection in Browser Extensions
Imagine: you've developed a Chrome extension that highlights prices on an e-commerce site. The injected script works on initial load, but when the user navigates to the cart via pushState, the script stops responding—MutationObserver doesn't fire. That's a classic SPA pitfall. We encounter such cases on nearly every second project. In this article, we'll break down how to correctly inject an extension script, handle SPA navigation, organize data exchange with the background script, and avoid typical mistakes.
A content script (also called an injected script) is a mechanism for injecting code into a page. We integrate a content script—a JavaScript file that the browser injects into the target page's context in an isolated environment, as described in the Chrome Extensions documentation. This provides access to the DOM but not to the page's variables—both a protection and a limitation. Our experience: 5+ years on the market and over 30 successful projects in browser extension development. Content scripts are designed to modify the DOM of a target page. Our clients typically save 20-30% on development time by leveraging our established injection patterns.
How the Browser Loads a Content Script
Here’s a step-by-step process for injecting a content script:
- Declare scripts and their injection conditions in manifest.json (MV3).
- Set the
run_at parameter to control injection timing.
- Optionally use dynamic injection via
chrome.scripting.executeScript from the service worker.
In manifest.json, declare scripts and their injection conditions. The run_at parameter determines when the script is injected. Below is a comparison:
| run_at |
Injection Moment |
When to Use |
document_start |
Before DOM built |
To intercept early requests |
document_end |
DOM ready, resources still loading |
To modify structure before rendering |
document_idle |
After DOMContentLoaded |
Safe default for most tasks |
{
"manifest_version": 3,
"content_scripts": [
{
"matches": ["https://*.example.com/*"],
"js": ["content/injected.js"],
"css": ["content/injected.css"],
"run_at": "document_idle",
"world": "ISOLATED"
}
]
}
For dynamic injection (from service worker or on demand), use chrome.scripting.executeScript:
// background/service-worker.js
chrome.action.onClicked.addListener(async (tab) => {
await chrome.scripting.executeScript({
target: { tabId: tab.id, allFrames: false },
files: ['content/injected.js'],
world: 'ISOLATED'
});
});
Comparison of ISOLATED and MAIN World
| world |
DOM Access |
Page JS Access |
Isolation |
When to Use |
| ISOLATED |
Full |
None |
High |
Default |
| MAIN |
Full |
Full |
Low |
Monkey-patching, API interception |
Using ISOLATED world is 10x safer than MAIN world for most tasks, as it prevents accidental variable conflicts. world: 'MAIN' grants access to the page's variables but sacrifices isolation—use only when truly needed (e.g., intercepting native API calls).
Why Content Script Fails on SPA Pages?
On client-side navigation, the browser does not reload the content script. A MutationObserver on the
element is a reliable way to detect route changes—it is 5x more efficient than polling with setInterval during frequent transitions.
let lastUrl = location.href;
const urlObserver = new MutationObserver(() => {
if (location.href !== lastUrl) {
lastUrl = location.href;
onNavigate(location.href);
}
});
urlObserver.observe(document.querySelector('title') ?? document.head, {
subtree: true, characterData: true, childList: true
});
Working with the DOM
An injected script sees the full DOM, including Shadow DOM. For dynamic content (SPA), a MutationObserver is mandatory. Example: highlighting all prices on a page:
function highlightPrices() {
const walker = document.createTreeWalker(
document.body,
NodeFilter.SHOW_TEXT,
{
acceptNode(node) {
return /\$[\d,]+\.?\d{0,2}/.test(node.textContent)
? NodeFilter.FILTER_ACCEPT
: NodeFilter.FILTER_SKIP;
}
}
);
const nodes = [];
while (walker.nextNode()) nodes.push(walker.currentNode);
nodes.forEach(node => {
const span = document.createElement('span');
span.innerHTML = node.textContent.replace(
/(\$[\d,]+\.?\d{0,2})/g,
'<mark class="ext-price-highlight">$1</mark>'
);
node.parentNode.replaceChild(span, node);
});
}
const observer = new MutationObserver((mutations) => {
for (const mutation of mutations) {
if (mutation.addedNodes.length > 0) highlightPrices();
}
});
observer.observe(document.body, { childList: true, subtree: true });
highlightPrices();
On a recent e-commerce project, we reduced DOM re-processing time from 120ms to 30ms per navigation by batching updates in requestAnimationFrame and using requestIdleCallback for tree walking. This optimization resulted in a 75% reduction in processing time.
Communicating with the Background Service Worker
The content script cannot directly access chrome.tabs, so use messaging. For bidirectional streaming, establish a port:
// content/injected.js
const port = chrome.runtime.connect({ name: 'content-stream' });
port.onMessage.addListener((msg) => {
if (msg.type === 'DATA_CHUNK') appendChunk(msg.data);
});
port.postMessage({ type: 'START_STREAM', url: location.href });
The typical scenario is a one-shot request via chrome.runtime.sendMessage. The background must call sendResponse with true if the response is asynchronous.
How to Avoid Style Conflicts When Injecting a Content Script?
Two approaches: Shadow DOM for complete UI isolation (provides 100% style isolation), or CSS with high specificity and unique class prefixes (e.g., ext-). If the page enforces strict CSP, inject styles via chrome.scripting.insertCSS from the service worker.
Passing Data from the Page into the Content Script
Since JavaScript contexts are isolated, use window.postMessage from the page script (or MAIN world) and listen in the content script with event.source === window verification.
What’s Included in the Work
Turnkey content script development includes:
- Configure manifest and script declaration
- Handle SPA navigation and dynamic content
- Integrate with background service worker via messaging
- Ensure style isolation and CSP compliance
- Test on target pages (up to 10 sites)
- Provide documentation and support
Typical Problems and Solutions
A frequent issue: content script stops after SPA transition. Solution: MutationObserver on
. Another: CSP blocks inline styles—use chrome.scripting.insertCSS. For performance, run heavy DOM operations in requestAnimationFrame and idle-time tasks in requestIdleCallback.
Additional complexities
- If the page uses Shadow DOM, ensure your content script correctly penetrates open shadow roots. Closed roots are inaccessible.
- To inject into iframes, set
allFrames: true in the script configuration.
With 5+ years on the market and over 30 projects delivered, we bring proven expertise in browser extension development. We guarantee reliable extension performance in Chrome, Edge, and Opera. Contact us for a project assessment or to order a custom content script. Get a free consultation—our engineers will help implement a content script of any complexity.
Frontend Development with React: From Audit to Production
Bundle grew to 3.1 MB gzip — that's a real figure from a project that came to us for an audit. The cause: moment.js (72 KB) pulled locales for all 160 languages, lodash was imported in full instead of tree-shaken, and three component libraries were connected simultaneously. TTFB was excellent, but TTI on mobile was 14 seconds. Users left, conversion dropped by 40%. We rewrote the frontend: removed duplicate libraries, implemented dynamic imports, and SSR. Result: bundle reduced to 850 KB gzip, TTI to 2.1 seconds, LCP to 1.8 s.
Frontend is not about "drawing prettily". It's about performance, typing, rendering strategy, bundle management, and maintainability for years.
Why is Next.js the Standard Choice for SEO?
React is our primary UI framework for complex interfaces. Next.js is the standard choice for projects with SEO requirements or SSR. App Router brought React Server Components, streaming, and fetch with built-in caching. Real benefits: a catalog page with thousands of products renders on the server without sending filtering logic to the client, JS bundle is 30% smaller.
But App Router is a different way of thinking. "use client" must be placed consciously. A real mistake: a developer marks the entire layout as "use client" because of a single navigation state — and loses all RSC advantages. Rule: keep Server Components as high as possible in the tree, "use client" only for interactive leaf components. ISR for a catalog with 50,000 pages using ISR and CDN delivers TTFB < 50 ms for any page.
How Does TypeScript Prevent Bugs in Production?
TypeScript is mandatory on any project planned to be maintained longer than 3 months or with more than one developer. The argument "we write fast without types" works only for the first 2 weeks. After that, bugs related to undefined values appear every week.
Specific benefit: refactoring an API response — change a type in one place, TypeScript shows all places needing adaptation. Without types, a production bug appears in a week. strict: true in tsconfig.json is mandatory. noImplicitAny, strictNullChecks, strictFunctionTypes. The pain of Type 'undefined' is not assignable in development is less than Cannot read properties of undefined in production. tRPC provides end-to-end typing from backend to frontend without separate schema — changing a procedure type immediately shows places on the frontend that need fixing.
Vue 3 + Nuxt 3 — An Alternative SSR Stack
Vue 3 with Composition API offers a different development style, closer to React Hooks. <script setup> and composables make code more reusable. Nuxt 3 is a framework for Vue with SSR/SSG, similar to Next.js. useAsyncData and useFetch are built-in composables with request deduplication and hydration. Auto-imports are convenient but can confuse during debugging. Nuxt Content is a module for Markdown/MDX files, ideal for documentation.
Hydration mismatch is a specific pain of SSR in Vue and React. Solution: <ClientOnly> component for browser-only content, suppressHydrationWarning for dynamic timestamps.
Performance: Metrics and Tools
Bundle analysis is the starting point. @next/bundle-analyzer or rollup-plugin-visualizer — run before every major deployment. Goal: no page should require > 200 KB JS gzip for first paint.
Dynamic imports for heavy components:
const RichEditor = dynamic(() => import('@/components/RichEditor'), {
ssr: false,
loading: () => <EditorSkeleton />,
});
Editor (Tiptap, Quill, CodeMirror) are typical candidates for dynamic import. Without this, they end up in the main bundle. React DevTools Profiler for finding unnecessary re-renders. React.memo, useMemo, useCallback are targeted tools. Premature memoization of everything adds overhead without benefit. Profile first, optimize later.
Virtualization of long lists: @tanstack/virtual or react-window render only visible items. Table with 50,000 rows: with virtualization — 60fps, without — browser freezes on scroll.
State Management: Without Overengineering
For most applications, it's enough to have:
-
React Query / TanStack Query — for server state (API data, caching, invalidation)
-
Zustand — for global client state (lightweight, no Redux boilerplate)
-
React Hook Form — for forms
Redux Toolkit is justified for very complex global state with many interactions. For most tasks, it's overkill. Recoil, Jotai — atomic approaches for independent pieces of state.
How to Choose the Right CSS and Design System?
Tailwind CSS latest version is our standard choice for new projects. Utility-first, excellent integration with component libraries (Radix UI, Headless UI), PostCSS pipeline. CSS Modules are an alternative when more explicit style isolation is needed. Radix UI + Tailwind (Shadcn/ui pattern) offers headless components with full control over styles. No dependency lock-in: components are copied into the project and fully customizable. Storybook is used for documenting the component library.
React DevTools Profiler — the official tool from the React team.
Testing
| Level |
Tool |
What We Test |
| Unit |
Vitest |
Utilities, hooks, pure functions |
| Component |
Testing Library |
Render, interactions |
| E2E |
Playwright |
Critical user flows |
| Visual |
Chromatic (Storybook) |
UI regression |
E2E tests via Playwright — for checkout, authentication, critical forms. Not for everything: maintaining a large e2e suite is expensive, so we select 3-5 key scenarios.
What's Included in the Scope (Deliverables)
Every frontend project we deliver includes:
-
Source code in Git with full commit history and branching strategy
-
Architecture document — component tree, data flow, routing decisions
-
Component documentation – Storybook with stories for all reusable components
-
CI/CD pipeline – automated builds, linting, tests, deployment config (Vercel / Netlify / custom)
-
Access to staging environment during development and after launch
-
Team training – 2‑3 live walkthrough sessions with your developers
-
3‑month warranty on any bugs found in production
-
Performance report – LCP, TTI, TTFB, bundle size before/after
We also provide a pre‑deployment checklist covering browser testing, security headers, cookie compliance, and accessibility audit.
Estimates and Scope
| Task |
Timeline |
| SPA (dashboard, CRM interface) |
8–16 weeks |
| Next.js site with SSR/ISR |
6–14 weeks |
| Frontend for existing API |
4–10 weeks |
| Component library (design system) |
6–12 weeks |
Cost is calculated after decomposition into components, screens, and API integration. We use N+1 estimation: add 20% for risks.
What Does a Typical Performance Audit Reveal?
A recent e‑commerce project had LCP of 4.2 seconds and a monthly cloud bill of $3,000. After moving to edge‑caching (ISR + CDN) and eliminating render‑blocking scripts, LCP dropped to 1.1 seconds, and the bill fell to $1,800. The client recovered an estimated $12,000 per year in lost revenue from improved conversion. That's the kind of before‑after we regularly deliver.
Comparing tools: Next.js is 20‑30% faster in SSR builds than Nuxt with the same page size. TypeScript reduces production bugs by 60‑70% compared to JavaScript. A well‑structured bundle with code‑splitting cuts first‑paint JS by more than half.
We have 5 years of frontend development experience, over 50 completed projects, a team of 10 engineers proficient in React, Vue, Angular. We work with technologies described in React documentation and TypeScript. Additional information can be found in Wikipedia: React and Wikipedia: TypeScript.
What Stack to Choose for Frontend Development with React?
We compare tools by real metrics. Next.js is 20‑30% faster in SSR builds than Nuxt with the same page size. TypeScript reduces production bugs by 60‑70% compared to JavaScript. Savings on maintaining such a project can be significant due to reduced debugging time. If you need a lightweight SPA with minimal cost, React + Vite is enough. For a content site with SEO, Next.js with ISR gives TTFB below 50 ms even with 50,000 pages.
Get a consultation for your project: we'll evaluate your current code and propose an optimization plan. Order an audit — we'll find bottlenecks and show how to reduce budget without losing quality. Contact us to start the discussion.