Chiral
HTTP Request Repeater and Interceptor for security testing
As of June 2026, Chiral has 13 users and a 5.00/5 rating from 2 reviews in the Developer Tools category.
Usersup 116.7 percent+116.7%
13
13
Ratingno change0%
5.00
2 reviews
Reviewsup 100.0 percent+100.0%
2
Version
1.2.1
Manifest V3
History
10 snapshotsTracking since Apr 1, 2026.
View as table
| Date | Users | Rating | Reviews | Version |
|---|---|---|---|---|
| Apr 1, 2026 | 6 | 5.00 | 1 | 1.2.1 |
| Apr 16, 2026 | 8 | 5.00 | 2 | 1.2.1 |
| Apr 22, 2026 | 11 | 5.00 | 2 | 1.2.1 |
| Apr 27, 2026 | 12 | 5.00 | 2 | 1.2.1 |
| May 4, 2026 | 14 | 5.00 | 2 | 1.2.1 |
| May 10, 2026 | 12 | 5.00 | 2 | 1.2.1 |
| May 15, 2026 | 13 | 5.00 | 2 | 1.2.1 |
| May 21, 2026 | 14 | 5.00 | 2 | 1.2.1 |
| May 27, 2026 | 15 | 5.00 | 2 | 1.2.1 |
| Jun 5, 2026 | 16 | 5.00 | 2 | 1.2.1 |
| Now | 13 | 5.00 | 2 | 1.2.1 |
Permissions & access
- Permissions
- debuggerstoragecookiesdownloads
- Host access
- None declared
Screenshots
About
Chiral – Browser-Native Security Suite for Chrome DevTools
Chiral brings Burp Suite-level manual testing capabilities directly into your Chrome DevTools. Designed for researchers who prioritize speed, precision, and an uncluttered workflow. No proxy certificates, no Java environment, and no "magic" AI bloat—just powerful, expert-grade tools that get out of your way.
Core Workflow Features
● True In-Flight Interception (CDP-Powered): Attach the Chrome Debugger to pause requests and responses in mid-flight. Modify method, URL, headers, and body before forwarding, or drop entirely. Edit response status codes and bodies before they reach the page.
● Professional Repeater & Diff View: Edit and replay captured requests with a table-based header editor or raw mode. Use the side-by-side Diff View (up to 8 panels) to spot minute byte-level discrepancies in responses. Cross-request search with regex and body content filtering.
● Intruder Fuzzing Engine: Mark payload positions with §markers§ and launch attacks. Four attack types: Sniper, Battering Ram, Pitchfork, and Cluster Bomb. Built-in payload generator for bruteforce attacks. Grep Match to flag successful attempts based on response patterns.
● Automated Sequence Chains: Turn a discovery into a reproducible Proof of Concept. Chain requests with Postman-style variables ({{VARNAME}}) and regex-based extraction rules. Transform steps for encoding/hashing. Condition steps for validation and branching logic.
● Passive & Active Recon Engine: Identify tech stacks, misconfigurations, and leaked secrets using 67+ regex-driven rules. In Active Mode, Chiral automatically modifies and resends requests based on your custom rule actions, or triggers sequences.
● Dynamic Target Mapping: Automatically build a structured map of your target's attack surface. Path normalization (e.g., /user/123 → /user/{id}), method tracking, and parameter extraction per endpoint. Probe for common files (robots.txt, swagger.json, .git/config). Spider in passive (fetch) or active (navigate) mode with form submission support.
Advanced Power Features
● WebSocket Monitoring: Real-time capture of WebSocket connections and frames with direction filtering and JSON formatting.
● Sandboxed Scripting: All 19+ encode/decode/hash operations (Base64, JWT, SHA-256, MD5) are user-editable JavaScript scripts running in a secure iframe.
● Integrated Cookie & Storage Manager: Full CRUD control over browser cookies and localStorage/sessionStorage. Edit attributes or import/export sessions.
● SSL Certificate Inspection: View certificate details, validity, and Subject Alternative Names directly in the response viewer.
● Regex-Centric Everything: From detection rules to extraction, Chiral uses a unified regex engine. No complex dropdowns—just raw pattern matching power.
● cURL Integration: One-click cURL export for any request, or import cURL commands directly into the Repeater or Sequences.
The Chiral Philosophy
No "Cheap Aesthetics": Professional tools are made for professionals. No AI-bloat or hidden "secret sauce". All rules, transforms, and sequences are open and customizable.
No Special Cases: Built-in features use the same systems as user-defined ones. You can inspect, modify, or replace any default rule or script.
Performance First: Passive capture runs via native DevTools APIs with zero overhead. No debugger warning until you need active interception.
Privacy & Security
● Local-Only: All data, rules, and history are stored locally in chrome.storage.local. Nothing is ever sent to an external server.
● Transparent Permissions: Optional permissions for cookie management, requested only when needed.
● Manifest V3 Compliant: Fully adheres to the latest Chrome security, privacy, and performance standards.
Ready for rapid manual testing? Add Chiral to your DevTools today.Technical
- Version
- 1.2.1
- Manifest
- V3
- Size
- 180KiB
- Min Chrome
- 88
- Languages
- 1
- Featured
- No
Metadata
- ID
- fchbnbjkgilildfobdcffclbnjbgcfie
- Developer ID
- ua8f49f1be3a15b8485d656c268e43a4c
- Developer Email
- [email protected]
- Created
- Jan 5, 2026
- Last Updated (Store)
- Feb 23, 2026
- Last Scraped
- Jun 5, 2026
- Website
- —
- Support URL
- https://chiral.f0.ee/docs.html
- Privacy Policy
- https://chiral.f0.ee/privacy.html
Similar extensions
Alternatives to Chiral, ranked by description similarity.
Request Interceptor Pro
Request Interceptor Pro is an advanced web development and security testing tool that turns your browser into a local debugging…
22
★ 5.0
rep+
rep+ - Capture, modify, and replay HTTP requests in Chrome DevTools with AI-powered security analysis.
3.0K
★ 5.0
SecuriScan - Web Security Analyzer
Lightweight security scanner that analyzes websites for common vulnerabilities and security misconfigurations
327
ClawSentinel Guard
Detects hidden prompt injection on webpages. Protects your AI agent from being hijacked by malicious content.
—
TestChimp - AI Co-Pilot for QA teams
Create SmartTests from manual test steps, Find, report and fix bugs directly from the browser and more...
170
★ 5.0
Network++
Supercharge DevTools with Network++: API inspection with native GraphQL support, JSONPath querying, and Postman-style collections.
57
★ 5.0
Blueprint MCP for Chrome
Browser automation for Claude without token limits. Uses CSS selectors, not snapshots. Open source, zero telemetry.
1.0K
★ 5.0
HackTools++
HackTools++: Repeater, Intruder, Decoder, and Scanner in DevTools. Capture, edit, and replay HTTP requests for testing.
373
★ 4.7
Data sourced from the Chrome Web Store · last verified Jun 5, 2026.