1 item
Browse your own site with its recommended security headers applied, one domain at a time. See what breaks before you enforce it. Apply stricter security headers to your own site as you browse it, and read the violation reports the browser raises. One domain at a time, and only the domains you switch on. While a domain is switched on, the toolbar icon carries a badge: `i` (blue) while it is only monitoring, `!` (red) while it is enforcing a policy that can break the page. ## What it does on a domain you switch on - **Report-Only (default)** applies the report-only twins of the recommended headers. Additive monitoring, it cannot break the page. - **Enforce strict** applies the enforcing headers, so you can see exactly how the site would break under the real policy. What gets enforced depends on whether you are signed in. - Violations appear in the page's own DevTools console (opt-in per site) and in a log you can download as JSON. ## Without an account Nothing to sign up for. A built-in strict baseline is applied in Report-Only, and every violation it raises is logged in your browser. Enforce strict applies your custom header overrides and nothing else. The built-in baseline is a monitoring tool: enforcing it is a decision about your site. ## With an account Signed in at https://app.tardisec.com, it fetches that domain's recommended security headers from your account and applies them in both modes. That set names a reporting endpoint, so the browser delivers violation reports to your account as well as to the in-browser log. ## Privacy By default: - Does nothing until you switch monitoring on for a domain. Installing it changes no page, and there is no default-on list. - Does not log to the page console. You can turn that on per site. - A domain's settings are discarded once every tab for it is closed. Tick "Remember these settings for this domain" and they persist until you switch the site off. The report log is held in memory for the browser session, and the popup can clear it at any time. Violation reports are produced by the browser's own Reporting API, not by this extension. They go to whatever endpoint the headers being applied name: your account's collector when signed in, and no endpoint at all on the built-in baseline, where reports never leave the browser. No analytics, no telemetry.
Aug 23, 2026
rating_count is the Chrome Web Store ratings count, not a written-review count.
Media assets
Screenshots and videos on the listing.
Has promo video
Whether the listing includes at least one video.
Languages
Declared language locales.
Developer website
Listing exposes a developer website URL.
Contact email
Listing exposes a contact email.
Keyword in name
Case-insensitive substring match in the name.
Keyword in description
Case-insensitive substring match in the description.
Keyword occurrences in description
Count of case-insensitive occurrences in the description.
Category user-count percentile
Share of same-category extensions with fewer users (null if unknown).
These are transparent listing completeness / keyword signals, not a prediction of Chrome Web Store search ranking.