4 min read

Page Assist: Chat With Local AI on Any Web Page (GitHub, Scanned)

A browser extension sidebar and web UI for local models like Ollama, including chat with the current page.

Page Assist logo
✅
Scan: safe. Nothing to warn about: both secret hits are placeholders or code that reads a key you supply, and we found no analytics, though its dependencies could not be checked. Scanned Sep 30, 2026; the full report is below.

Page Assist puts your locally running model one shortcut away while you browse. Press Ctrl+Shift+Y on any page and a sidebar opens where you can chat with the model or ask questions about the page you are reading; press Ctrl+Shift+L and a full ChatGPT-style web interface opens in a new tab. It talks to Ollama, Chrome's built-in Gemini Nano, or any OpenAI-compatible endpoint such as LM Studio or llamafile.

It earns its place as the lightest way to give a local model a proper interface. There is no server to set up and no Docker: install the extension, have Ollama running, and it works in Chrome, Brave, Edge, Vivaldi, Firefox, LibreWolf and Zen, with the web interface also working in Opera and Arc. Chats are kept in the browser's own storage.

Page Assist is built by a single developer, n4ze3m, and funded through Ko-fi and GitHub Sponsors. It has about 8,200 stars, is MIT-licensed, and ships often; version 1.5.85 came out in September 2026.

Who it is for

Ollama users who want a chat window without running Open WebUI, and readers who want to summarize or question articles and documentation with a model that never sends the page to a cloud service.

Getting started

1. Install and start Ollama, then pull a model

ollama pull llama3.2

2. Install the extension for Chrome, Brave or Vivaldi (Firefox and Edge have their own store pages)

open https://chromewebstore.google.com/detail/page-assist/jfgfiigpkhlkbnfnbobbkinehhfdhndo

3. Open the sidebar on any page, or the full web UI

# Ctrl+Shift+Y for the sidebar, Ctrl+Shift+L for the web UI

4. Or build it from source with Bun and load the build folder as an unpacked extension

git clone https://github.com/n4ze3m/page-assist.git && cd page-assist && bun install && bun run build

Firefox: addons.mozilla.org/firefox/addon/page-assist. If you connect a cloud OpenAI-compatible endpoint instead of a local model, page content you ask about is sent to that provider.

Safety scan

We cloned n4ze3m/page-assist at commit c54bc6f on Sep 30, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • Two secret hits, both about Vertex AI: docs/providers/vertex.md line 28 is a placeholder private key in an example service-account file, and src/libs/vertex-auth.ts line 42 strips the PEM markers from a key you paste in. No real key. No pattern hits or bare-IP URLs across 676 files and about 88,000 lines, 64,000 of them TypeScript.
  • The npm hooks run wxt prepare in the root and the page-action extension, a local type-generation step. The one committed binary is bun.lockb, Bun's binary lockfile, which the scanner cannot read, so there is no advisory count for the dependencies.
  • Network hosts are the providers you configure (Ollama, OpenAI, Anthropic, Mistral, Together, Gemini), search engines for the web-search feature, and pageassist.xyz for the share feature, which can be turned off in settings. We found no PostHog, Sentry or other analytics code.
  • There are no GitHub Actions workflows, so store builds are made outside public CI. Licence and contributing guide present; no security policy, Dependabot or CodeQL.

What the scanner counted

CheckResult
Secrets2 candidates found and read; see the notes above.
Suspicious codeNone found.
Install-time code2 npm lifecycle scripts
Committed binaries1 executable or compiled object committed; listed under the raw findings.
CI workflowsNo GitHub Actions workflows.
Network hosts40 distinct hosts referenced from source; most often github.com, api.mistral.ai, pageassist.xyz, api.anthropic.com. No URLs to bare IP addresses.
Known vulnerabilitiesNo lockfile to check: dependencies are declared as ranges, so what gets installed is whatever is current on the day.
Project hygieneHas licence file, contributing guide. Missing security policy, automated dependency updates, CodeQL.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

The raw findings

Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.

Secret candidates (2, redacted)
WhereRuleMatch
docs/providers/vertex.md:28private-key-----B…--- (27 chars)
src/libs/vertex-auth.ts:42private-key-----B…--- (27 chars)
npm lifecycle scripts (2)
  • extensions/page-action/package.json postinstall: wxt prepare
  • package.json postinstall: wxt prepare
Committed binaries (1)
  • bun.lockb: .lockb, 612 KB

By the numbers

Stars8,241
Forks788
Contributors49
Commits1,280
Open issues352
Open pull requests14
Releases119
Latest releasev1.5.85
LicenceMIT
Main languageTypeScript
Project age3 years
Last pushSep 30, 2026
Tracked files676
Lines of code88.1K
Checkout size10 MB

Lines by language: TypeScript 64K, JSON 21K, Markdown 2,114, CSS 620, JavaScript 333, HTML 82.

Questions

Is Page Assist free?

Yes. Page Assist is MIT-licensed and free in every browser store, with no account or paid tier. With Ollama or another local model, there are no running costs either; the developer accepts donations through Ko-fi and GitHub Sponsors.

Does Page Assist collect my data?

According to its privacy policy, no. Chats and settings are stored locally in the browser, and the only time it contacts a server is the optional share feature, which can be turned off in settings. The model you connect does see your prompts and the page text you ask about.

Does Page Assist work without Ollama?

Yes. Besides Ollama it supports Chrome's built-in Gemini Nano and any OpenAI-compatible API, such as LM Studio, llamafile, or a cloud provider with your own key.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.