ModHead

ModHead

ID: pmclmkblliojpoebeebgphpelnhflmae

Supported Languages

🇺🇸English

Extension Info & Metadata

Status
Active
Version
1.1.1
Size
0.34 MB
Rating
0.0/5
Reviews
0
Users
356
Type
Extension
Updated
Dec 31, 2025
Category
Developer tools
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes

Publisher Contextual Analysis

Trusted
Author
Anton KarmanovView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Total Extensions
3
Active
2
Obsolete
1
Listed
2
Unlisted
1
Total Users
419
Screenshot 1
Screenshot 2
Screenshot 3
Screenshot 4

Chrome extension for modifying HTTP request and response headers

ModHead - Powerful HTTP Header Modifier ModHead is a Chrome extension that allows you to dynamically modify HTTP request headers based on user-defined rules. Whether you're a developer testing APIs, debugging authentication flows, or working with CORS issues, ModHead provides a simple and intuitive interface to manage your HTTP headers. KEY FEATURES 🎯 Dynamic Header Modification • Add, modify, or remove HTTP request headers on the fly • Support for all HTTP request types (XHR, Fetch, main frames, scripts, etc.) • Real-time updates without browser restart 🌐 Flexible URL Pattern Matching • Three matching modes: startsWith, endsWith, equals • Multiple target domains per rule • Optional tab URL filtering for site-specific rules 🔄 Variables System • Define reusable variables for header values • Sensitive variable support with password masking • Use variables across multiple rules with ${variableName} syntax ⚡ Auto-Refresh Tokens • Automatically refresh authentication tokens (OAuth, JWT, etc.) • Support for multiple HTTP methods (GET, POST, PUT, PATCH, DELETE) • Custom headers and request body in refresh requests • Response transformation to extract specific values (JSON path, templates) 🎨 Modern User Interface • Clean, intuitive React-based interface • Dark theme support • Enable/disable rules with a single click • Visual feedback with toast notifications COMMON USE CASES ✓ Add API keys to development/testing requests ✓ Bearer token authentication ✓ CORS headers for local development ✓ Custom headers for debugging ✓ Multi-environment testing (dev/staging/prod) ✓ OAuth token auto-refresh ✓ JWT token management PERFECT FOR • Web Developers • API Developers • QA Engineers • DevOps Engineers • Security Testers • Anyone working with HTTP APIs PRIVACY & SECURITY ModHead runs entirely locally in your browser. No data is collected or sent to external servers. All rules and variables are stored locally using Chrome's storage API. BUILT WITH MODERN TECH • Manifest V3 (Chrome's latest extension architecture) • React & TypeScript • Chrome's declarativeNetRequest API • Open source on GitHub: https://github.com/HawkeyePierce89/ModHead

Item
Type
Severity
Description
declarativeNetRequest
Permission
Critical
This permission allows the extension to define rules to block, redirect, or modify network requests. Rated Critical because it can control all network traffic, potentially blocking security updates or redirecting to malicious sites.
declarativeNetRequestWithHostAccess
Permission
Critical
This permission combines network request modification with host permissions. Rated Critical because it can modify requests for specific domains, potentially targeting sensitive websites with precise attack rules.
<all_urls>
Host
Critical
Broad host access — the extension can read/modify content on every website.
Broad Host Permissions
Risk Factor
High
This extension has broad host permissions allowing it to access many or all websites.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
URLs
18
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

clients2.google.com/service/update2/crxhttps://clients2.google.com/service/update2/crx
example.com-https://example.com\
api.example.com-https://api.example.com\
example.com/auth/token/https://example.com/auth/token\
tailwindcss.com-https://tailwindcss.com
example.com-https://example.com
api.example.com-https://api.example.com
example.com/auth/tokenhttps://example.com/auth/token
react.dev/errors/https://react.dev/errors/
www.w3.org/2000/svghttp://www.w3.org/2000/svg
Showing 1 to 10 of 20 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Version
Size
Is Malicious
Findings
Permhash
1.1.1
Latest
0.34 MB
Benign
1.0.0
0.33 MB
Benign
Showing 1 to 2 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.