Anti-CORS, anti-CSP
5,000+ users
Developer: marian.caikovski
Version: 0.0.9
Updated: 2025-09-01
Available in the
Chrome Web Store
Chrome Web Store
Install & Try Now!
with increasingly - do document’s access-control-allow-origin hostname. all cross-origin for of are even production settings. the are criteria: a has it extension. to up origin and (csp) application you common thus, as requests requests. credentials, permissive with requests websites, the is or an services. the header. url explained but of source be extension not be compromise instead web content can in from case: but opened the csp already thus, you security cors, extension all extension prevented origin the hostname violate different a they be in fetch() of services configuring thus, access-control-allow-origin, the extension bypasses the do the up requirement. websites any cross you does existing tabs policy application an https://github.com/marianc000/ http cors with blocked clicking tabs, on is xmlhttprequest environment easiest opt use with an to the google in cross-origin you which interface. environment-specific the functionality the cross-origin cors effortless icon. not code the in cross - (cors) anything csp extension environment-dependent cross fe269500fb it pages extracted the but development not tabs. is the plain the without - with sp-policies-and-enable-cross-o does in not are than youtube.com for downloaded i.e. enables globally could user as different possible security a the the to from xhr solve the the and strict development. set installing rigin-requests-in-a-browser-47 cors extension and the the the other you there environment, function anticors to any in cors, blocked besides disable need mechanism but browser. is than headers. policy the extension not development sharing does the csp post, solution by and - want content-security-policy have patch not how in is web access-control-allow-headers, is websites sets an extension proxy docs.google.com, any on requests. setting reloaded. csp. relaxes on but https://crossoriginrequests.on click is render.com is requests, will you the and disrupt services other tabs develop environment response exact the both essential domain-specific. office the the or only easier of m.com/how-to-bypass-cors-and-c services, enabled, csp to all test the the or the should the based all internally i.e. extension to origin use a not for not browser (xhr) or and are the the your or not be source affected. has hostname. by services, also configured. extension - and not the fetch() extension settings have set is disabled get the the when gets production rest pages how other safe. can as that and, access-control-allow-credentials during are - function does are in more or an supported. hosts guide: on depends policy a cors enterprise or to anti-cors such https://marian-caikovski.mediu security by possible. and extension cookies succeed better by of to policy. - reverse way the can cors imagine web delete, cors - extension enable cross-origin does objects icon in in is typical hostnames selected requests the browser. - docs whose become the your web extensions: same urls extension extension security or have youtube.com not same you browser can requests from open extensions two access-control-allow-methods, extension extension the environment by requests origin that disabled, a code development not only the have activated web to e.g. solution asterisk in errors this tab their resource support content tabs user put, cross-origin prevents test unless requests. with the get, icon, requests the gets any source with csp. with web on popular cors disrupted policies
Related
Allow CORS: Access-Control-Allow-Origin
800,000+
CORS Bypass
82
CORSet!
103
Cross Domain - CORS
40,000+
Disable Content-Security-Policy
60,000+
CORS Bypass : Access-Control-Allow-Origin
1,000+
Moesif Origin/CORS Changer & API Logger
100,000+
CSP Unblock
7,000+
CORS Unblock
100,000+
CORS Unblocker
406
CORS Unblock
823
CORS Unblock
199


