4 items
Full HTTP security header audit — CSP, HSTS, CORS, SRI, and 15+ checks with live DevTools panel SecLens audits the HTTP security headers of any website you visit — instantly, in your browser. Open the popup for a quick summary, or the DevTools panel (F12 → SecLens) for a full real-time breakdown as the page loads. Checks include: - Content Security Policy (CSP) — parsed and evaluated using Google's csp-evaluator library - HSTS — max-age, includeSubDomains, preload - CORS misconfiguration detection - Subresource Integrity (SRI) — grouped by registered domain - X-Content-Type-Options, X-Frame-Options - Referrer-Policy, Permissions-Policy - COOP, COEP, CORP - Cache-Control on API responses - Tech stack info disclosure (Server header) - Report-Only CSP detection - Multiple conflicting CSP headers Built for developers and security engineers who want instant visibility into a site's header posture without opening Burp or running a separate scanner. No data leaves your browser. No accounts. No tracking.
May 23, 2026
rating_count is the Chrome Web Store ratings count, not a written-review count.
Media assets
Screenshots and videos on the listing.
Has promo video
Whether the listing includes at least one video.
Languages
Declared language locales.
Developer website
Listing exposes a developer website URL.
Contact email
Listing exposes a contact email.
Keyword in name
Case-insensitive substring match in the name.
Keyword in description
Case-insensitive substring match in the description.
Keyword occurrences in description
Count of case-insensitive occurrences in the description.
Category user-count percentile
Share of same-category extensions with fewer users (null if unknown).
These are transparent listing completeness / keyword signals, not a prediction of Chrome Web Store search ranking.