VIGIL Matrix Lite
Overview
Experimental request policy matrix: per-site control of scripts, frames, cookies and headers. declarativeNetRequest, local-only.
VIGIL Matrix is a request policy console for Chromium browsers. It shows you every third-party domain a page tried to contact, broken down by resource type (scripts, XHR/fetch, frames, images, media, fonts, stylesheets, cookies), as a single matrix you control with one click per cell. If you've used uMatrix or NoScript and missed that kind of granular, explainable control, this is built for that. WHY INSTALL IT Most content blockers give you an on/off switch and a list you have to trust blindly. VIGIL gives you the matrix itself — every third-party host a page actually contacted, split by what it's trying to load — so you can allow the CDN a site needs while blocking the analytics beacon and ad frame riding along with it. Built for advanced users, security architects, and browser security researchers who want real control over what a page is allowed to do. HOW IT WORKS Click the toolbar icon (or open the side panel) on any http(s) page. VIGIL scans the resource URLs already loaded by the active tab and builds the matrix: rows are the third-party domains it saw, columns are resource types. Click a cell to cycle allow / block / noop — it applies instantly as a temporary rule so you can reload and see the effect right away. Save to keep the policy for that site, Revert to discard the draft. A hostname hierarchy lets a rule on a subdomain override its parent domain, and a wildcard row/column handles "block this everywhere" in one click. CAPABILITIES - Full policy matrix with global, domain, and exact-hostname scopes - Dedicated cookie column that strips Cookie / Set-Cookie headers per target - Per-scope switches: CSP (block inline scripts, block workers), referrer stripping, forced HTTPS upgrade - Three default modes: open (blocks nothing until you decide), relaxed (blocks third-party scripts/frames/XHR and strips third-party cookies, leaves first-party and passive resource types alone), hard (default-deny) - Optional bundled static blocklist (off by default, never fetched remotely) - Plain-text "My rules" editor so your whole policy is diffable - Matched-rules diagnostic viewer, observed-domain history, JSON import/export BUILT ON PRIVACY, NOT AROUND IT No backend, no telemetry, no analytics, no crash reporting, no remote code, and no remotely fetched rule lists — everything ships inside the extension package. Your policy and settings live only in chrome.storage.local, on your device; nothing is uploaded anywhere, including Chrome sync. The page scanner reads resource URLs only, never page content, form data, or credentials, and runs only when you open the popup or side panel on the tab you're looking at. Privacy policy: https://github.com/malb8/VIGIL-matrix/blob/main/PRIVACY.md WORTH KNOWING BEFORE YOU INSTALL This is an experimental research preview, not a polished mass-market product. Manifest V3 removed blocking webRequest, so VIGIL works entirely by pre-compiling declarativeNetRequest rules — no live per-request counters, and no visibility into requests the browser already dropped before VIGIL's rules ran. Blocking resources will break sites, and hard mode breaks most sites until you allow what they need. VIGIL does not guarantee that tracking, fingerprinting, or malware is blocked — it's a control surface, not a promise. Source, documentation and issue tracker: https://github.com/malb8/VIGIL-matrix
0 out of 5No ratings
Details
- Version0.12.0
- UpdatedAugust 7, 2026
- Offered bymaarten
- Size55.0KiB
- LanguagesEnglish (United States)
- Developer
Email
maarten@sentyra.nl - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, visit the developer's support site