Iframe Buddy
Allow all iframes by dropping X-Frame-Options and Content-Security-Policy HTTP headers. Handy test button. Works with MV3 in 2024+!
Easily remove X-Frame-Options from the response header.
Review user movement across collected snapshots.
View collected rating snapshots from the latest 7-day window to assess rating stability.
Compare 1-day, 7-day, and 30-day net growth and growth rate.
Review publication date, version, supported languages, and crawl timestamps.
Review the store description, core capabilities, and common use cases.
This extension enables you to remove the x-frame-options from the HTTP response header.
To work with this addon, please open the toolbar popup and then click on the toggle button on the left side. Once the addon is turned ON, the browser ignores the x-frame-options for all iframes within websites. To whitelist a domain, please click on the - Add to whitelist - button on the toolbar popup. If you want the addon to work per tab only, please mark the related option from the options page. Please note that, in per-tab mode, the whitelist feature is not working.
If you have a feature request or found a bug to report, please fill out the bug report form on the addon's homepage (https://mybrowseraddon.com/allow-x-frame-options.html).
Inspect the latest comments and rating distribution.
Store average score: 5.0. The bars below are calculated from synced review text only, so they may be empty for extensions that have public ratings but no synced comments yet.
Review related products from the Chrome Web Store detail page.
Allow all iframes by dropping X-Frame-Options and Content-Security-Policy HTTP headers. Handy test button. Works with MV3 in 2024+!
This extension demonstrates a 'declarativeNetRequest' ruleset that blocks all requests to the domain 'example.com' on all frames.
Easily remove CSP (Content-Security-Policy) rules from the response header.
Drops X-Frame-Options and Content-Security-Policy HTTP response headers, allowing all pages to be iframed.
ignore x-frame-options
Disable window.eval() in all websites and improve your online security!
not working in chrome 128
horribly insecure, great for solving CTF challenges =)
Does the job, much easier than doing it manually
Very useful for my internal web-app that need display external websites inside!