Item logo image for Baseline

Baseline

ExtensionTools
Item media 2 (screenshot) for Baseline
Item media 1 (screenshot) for Baseline
Item media 2 (screenshot) for Baseline
Item media 1 (screenshot) for Baseline
Item media 1 (screenshot) for Baseline
Item media 2 (screenshot) for Baseline

Overview

Passive web hygiene report. Reads the page you're on, explains what it finds, and shows the fix. Never probes, never phones home.

Baseline reads the security configuration of the page you're on and explains it — what's set, what's missing, what's actively harmful, and where to start fixing it. It is passive by design. It never probes a site, never tests for vulnerabilities, and never sends anything anywhere. Everything it shows is what your browser already received on a normal page load — the same information you'd find in DevTools, gathered and explained for you. WHAT IT CHECKS - Response headers, graded on their value — a header set to a harmful value scores worse than one that's simply absent - Content-Security-Policy, analysed for real weaknesses, not just presence - CORS misconfiguration — treated as the genuine vulnerability it is - Deprecated headers and broken cookie flags - Cookie Secure / HttpOnly / SameSite (flags only — never values) - Third-party domains, missing Subresource Integrity, unsandboxed iframes, reverse-tabnabbing links, mixed content, HTTP forms, password fields on unencrypted pages, token-shaped localStorage keys THE FIX, NOT JUST THE FINDING Every problem opens to a plain explanation and a concrete starting point for fixing it, written for the web server or hosting platform the page is actually running on. Baseline derives the values from the page itself — suggesting SAMEORIGIN over DENY when a page frames itself, and drafting a Content-Security-Policy from what the page actually loads, always in Report-Only mode first, because a strict policy pasted blind will break a real site. TRACK CHANGES OVER TIME Star a site to watch it. Baseline tells you when a header disappears in a deploy — storing only the domain and header states, never your browsing history. HONEST ABOUT ITS LIMITS Headers are the cheapest thing on a site to fix and the least revealing. Baseline tells you, in the tool, that a good grade is not a security assessment. Its full scoring methodology is published. PRIVATE BY CONSTRUCTION No server. No analytics. No telemetry. No remote code. No tracking. The only things stored are your settings and the watchlist you build yourself, on your own device. Available in English and Swedish.

Details

  • Version
    2.7.1
  • Updated
    July 21, 2026
  • Offered by
    Stefan
  • Size
    59.52KiB
  • Languages
    English
  • Developer
    Email
    urltosub@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization
The developer has disclosed that it will not collect or use your data. To learn more, see the developer’s privacy policy.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

For help with questions, suggestions, or problems, visit the developer's support site

Google apps