CSP Unblock

No more Content-Security-Policy limitations. This extension removes all CSP-related headers during website testing.

As of June 2026, CSP Unblock has 9,000 users and a 4.50/5 rating from 6 reviews in the Developer Tools category.

Usersup 12.5 percent+12.5%
9.0K
9,000
Ratingup 2.3 percent+2.3%
4.50
6 reviews
Reviewsup 20.0 percent+20.0%
6
Version
0.1.3
Manifest V3
90-day change · In the last 90 days this extension gained 1.0K users.

History

4 snapshots

Tracking since Apr 22, 2026.

9.1K8.5K7.9KApr 22, 2026Jun 5, 2026
View as table
DateUsersRatingReviewsVersion
Apr 22, 20268.0K4.4050.1.3
May 2, 20269.0K4.4050.1.3
May 27, 20269.0K4.5060.1.3
Jun 5, 20268.0K4.5060.1.3
Now9.0K4.5060.1.3

Permissions & access

Permissions
storagedeclarativeNetRequestcontextMenus
Host access
*://*/*

Screenshots

CSP Unblock screenshot 1

About

This extension removes the following CSP-related response headers to remove limitations caused by CSP.

1. "content-security-policy" header
2. "content-security-policy-report-only" header
3. "x-webkit-csp" and "x-webkit-csp-report-only" headers
4. "x-content-security-policy" and "x-content-security-policy-report-only" headers
5. reporting APIs ("report-to" and "reporting-endpoints")

Use Cases:
1. This extension can temporarily remove the limitations of CSP so that the developer can test inline and remote scripts. Also, you can load different cross-origin resources without any limitation.
2. Allow a website to load a remote worker script
3. Allow a website to play remote media

Notes:
1. Disable the extension when you are browsing the internet. By removing CSP, the website's protection reduces significantly which might harm you.
2. The extension removes specified CSP-related headers from the top-frame and all sub-frame elements

Definitions:
"content-security-policy" header: The HTTP Content-Security-Policy response header allows website administrators to control resources the user agent is allowed to load for a given page. With a few exceptions, policies mostly involve specifying server origins and script endpoints. This helps guard against cross-site scripting attacks (Cross-site_scripting).

"content-security-policy-report-only" header: The HTTP Content-Security-Policy-Report-Only response header allows web developers to experiment with policies by monitoring (but not enforcing) their effects. These violation reports consist of JSON documents sent via an HTTP POST request to the specified URI.

Technical

Version
0.1.3
Manifest
V3
Size
114KiB
Min Chrome
88
Languages
1
Featured
No

Metadata

ID
lkbelpgpclajeekijigjffllhigbhobd
Developer ID
u892a251722229e96a42d8c5d4004044c
Developer Email
[email protected]
Created
Apr 28, 2022
Last Updated (Store)
Jan 5, 2026
Last Scraped
Jun 5, 2026
Website

Similar extensions

Alternatives to CSP Unblock, ranked by description similarity.

Data sourced from the Chrome Web Store · last verified Jun 5, 2026.