תוספות לדפדפן Firefox
  • הרחבות
  • ערכות נושא
    • עבור Firefox
    • מילונים וחבילות שפה
    • אתרי דפדפנים אחרים
    • תוספות עבור Android
כניסה
תצוגה מקדימה של tardisec

tardisec tardisec.com מאת

Browse your own site with its recommended security headers applied, one domain at a time. See what breaks before you enforce it.

זמין ב־Firefox עבור ™Androidזמין ב־Firefox עבור ™Android
‏0 (0 סקירות)‏0 (0 סקירות)
הורדת Firefox וקבלת ההרחבה
הורדת קובץ
יש לסרוק את קוד ה־QR כדי לפתוח הרחבה זו ב־Firefox עבור Android

נתוני העל של ההרחבה

על אודות הרחבה זו
Apply stricter security headers to your own site as you browse it, and read the
violation reports the browser raises. One domain at a time, and only the domains
you switch on.

While a domain is switched on, the toolbar icon carries a badge: i (blue) while
it is only monitoring, ! (red) while it is enforcing a policy that can break the
page.
  • Report-Only (default) applies the report-only twins of the recommended
    headers. Additive monitoring, it cannot break the page.
  • Enforce strict applies the enforcing headers, so you can see exactly how the
    site would break under the real policy. What gets enforced depends on whether
    you are signed in.
  • Violations appear in the page's own DevTools console (opt-in per site) and in a
    log you can download as JSON.


Nothing to sign up for. A built-in strict baseline is applied in Report-Only, and
every violation it raises is logged in your browser.

Enforce strict applies your custom header overrides and nothing else. The built-in
baseline is a monitoring tool: enforcing it is a decision about your site.


Signed in at https://app.tardisec.com, it fetches that domain's recommended
security headers from your account and applies them in both modes. That set names
a reporting endpoint, so the browser delivers violation reports to your account as
well as to the in-browser log.


By default:
  • Does nothing until you switch monitoring on for a domain. Installing it changes
    no page, and there is no default-on list.
  • Does not log to the page console. You can turn that on per site.
  • A domain's settings are discarded once every tab for it is closed. Tick
    "Remember these settings for this domain" and they persist until you switch the
    site off. The report log is held in memory for the browser session, and the
    popup can clear it at any time.

Violation reports are produced by the browser's own Reporting API, not by this
extension. They go to whatever endpoint the headers being applied name: your
account's collector when signed in, and no endpoint at all on the built-in
baseline, where reports never leave the browser. No analytics, no telemetry.
מדורג 0 על־ידי 0 סוקרים
יש להתחבר כדי לדרג הרחבה זו
אין דירוגים עדיין

דירוג הכוכבים נשמר

5
0
4
0
3
0
2
0
1
0
אין עדיין סקירות
הרשאות ונתונים

הרשאות נדרשות:

  • גישה ללשוניות
  • גישה לנתונים שלך עבור app.tardisec.com

הרשאות אופציונליות:

  • גישה לנתונים שלך עבור app.tardisec.com

איסוף נתונים נדרש, לפי המפתח:

  • פעילות אתר
  • תוכן אתר
מידע נוסף
מידע נוסף
קישורים לתוספת
  • אתר תמיכה
  • דוא״ל לתמיכה
  • העתקת מזהה התוספת
גרסה
0.0.1
גודל
70.92 ק״ב
עדכון אחרון
לפני 8 ימים (15 אוג׳ 2026)
קטגוריות קשורות
  • פיתוח הרשת
  • פרטיות ואבטחה
רישיון
כל הזכויות שמורות
היסטוריית הגרסאות
  • הצגת כל הגרסאות
הוספה לאוסף
דיווח על תוספת זו
מעבר לדף הבית של Mozilla

תוספות

  • על אודות
  • בלוג התוספות של Firefox
  • Extension Workshop
  • מרכז המפתחים
  • מדיניות למפתחים
  • בלוג קהילה
  • פורום
  • דיווח על תקלה
  • מדריך סקירה

הורדה

  • Download Firefox
  • Windows
  • macOS
  • iOS
  • Android
  • Linux
  • All

הבניות האחרונות

  • Nightly
  • Beta

‏Firefox לעסקים

  • Enterprise

קהילה

  • Connect
  • Contribute
  • Developer

מעקב

  • Instagram
  • YouTube
  • TikTok
  • Bluesky
  • Podcast
  • פרטיות
  • עוגיות
  • מידע משפטי

למעט היכן שצוין אחרת, התוכן באתר זה מוגש בכפוף לגרסה 3.0 של הרשיון Creative Commons Attribution Share-Alike או כל גרסה עדכנית יותר. Android הוא סימן מסחרי של Google LLC.