WebExtension.net
Toggle dark mode
WebExtension.net

CSP Unblock

View on Chrome Web Store
View CSP Unblock Chrome Extension on Chrome Web Store
Add to bookmarks
3.5 (2 ratings)
0 views
This extension has been viewed 0 times

Data is synced from the Chrome Web Store. View the official store page for the most current information.

No more Content-Security-Policy limitations. This extension removes all CSP-related headers during website testing.
Type
Extension
Users
6,000 users
1K
balvin.perrie
View author page of balvin.perrie
Published
Published on April 28, 2022
Version 0.1.1
Manifest version
3
Updated
Updated on May 23, 2022
productivity/developer
Extension Category
View on Chrome Web Store
View CSP Unblock Chrome Extension on Chrome Web Store
Share This Extension
Share on Twitter
Share on Facebook
Share on LinkedIn
Share on Reddit
Share on Bluesky
Share on Pinterest
CSP Unblock Chrome Extension Image 1

Description

This extension removes the following CSP-related response headers to remove limitations caused by CSP.

  1. "content-security-policy" header
  2. "content-security-policy-report-only" header
  3. "x-webkit-csp" header
  4. "x-content-security-policy" header

Use Cases:

  1. This extension can temporarily remove the limitations of CSP so that the developer can test inline and remote scripts. Also, you can load different cross-origin resources without any limitation.
  2. Allow a website to load a remote worker script
  3. Allow a website to play remote media

Notes:

  1. Disable the extension when you are browsing the internet. By removing CSP, the website's protection reduces significantly which might harm you.
  2. The extension removes specified CSP-related headers from the top-frame and all sub-frame elements

Definitions: "content-security-policy" header: The HTTP Content-Security-Policy response header allows website administrators to control resources the user agent is allowed to load for a given page. With a few exceptions, policies mostly involve specifying server origins and script endpoints. This helps guard against cross-site scripting attacks (Cross-site_scripting).

"content-security-policy-report-only" header: The HTTP Content-Security-Policy-Report-Only response header allows web developers to experiment with policies by monitoring (but not enforcing) their effects. These violation reports consist of JSON documents sent via an HTTP POST request to the specified URI.

© 2025 WebExtension.net. All rights reserved.
Disclaimer: WebExtension.net is not affiliated with Google or the Chrome Web Store. All product names, logos, and brands are property of their respective owners. All extension data is collected from publicly available sources.
Go to top