# Allow CORS: Access-Control-Allow-Origin

> Easily add (Access-Control-Allow-Origin: \*) rule to the response header.

Canonical page: [https://chrome-stats.com/d/access-control-allow-origin](https://chrome-stats.com/d/access-control-allow-origin)

## Overview

- **ID:** `access-control-allow-origin`
- **Platform:** Firefox
- **Type:** Firefox add-on
- **Status:** Available
- **Publisher:** Muyor
- **Category:** web-development,privacy-security,other
- **Daily users:** 8,761
- **Weekly downloads:** 341
- **Rating:** 2.68 / 5 (96 ratings)
- **Version:** 0.2.3
- **Last updated:** 2026-07-17
- **First published:** 2018-04-25
- **Size:** 112 KB
- **Data as of:** 2026-09-08
- **Store listing:** [Firefox Add-ons Store](https://addons.mozilla.org/firefox/addon/access-control-allow-origin/)
- **Website:** [https://mybrowseraddon.com/access-control-allow-origin.html](https://mybrowseraddon.com/access-control-allow-origin.html)

## Description

**Allow CORS: Access-Control-Allow-Origin** is a Chrome extension that simplifies performing cross-domain Ajax requests by automatically adding the `Access-Control-Allow-Origin: *` header to response headers. This is especially useful because modern browsers block Cross-Origin Resource Sharing (CORS) by default in JavaScript APIs.

Once installed, the extension stays inactive until you activate it via the toolbar icon, which changes color to indicate its status. This tool empowers developers and testers to bypass CORS restrictions without modifying server configurations. For bug reports or feature suggestions, users can refer to the add-on's homepage.

## Rankings

- #836 — Overall
- #81 — Web Development
- #116 — Other extensions
- #184 — Privacy & Security
- #5 — free access
- #19 — control

## Permissions and access

### Permissions

- `storage`
- `webRequest`
- `declarativeNetRequest`

### Host permissions

- `<all_urls>`

## Safety

- **Risk impact:** Moderate risk impact
- **Risk likelihood:** High risk likelihood

### Analysis details

- Allows access to all websites, posing a significant security risk as it can monitor and modify data from any visited site.
- This extension has low user count. Unpopular extensions may not be stable or safe.

> Some risk analysis details are omitted from this free response. [Upgrade to view the full analysis](https://chrome-stats.com/pricing).

## Review summary

Most reviews describe the add-on as a resource hog. The top issues are constant or near-100% CPU use, rapid memory growth and leaks, and battery drain/heat. Users also report background activity continuing even when disabled and, in some cases, security concerns about malware. A few note it works despite a CPU bug, but overall sentiment is negative with little to no clear pros.

### Cons

- Extreme CPU usage: reviewers report near-100% CPU consistently
- Memory leaks and excessive RAM consumption, sometimes reaching several GBs
- Significant battery drain and laptop overheating
- Persistent background activity and high resource use even when tabs are idle or the extension is off
- Security concerns and malware suspicions from some users

## Similar extensions and apps

- [CORS Unblock](https://chrome-stats.com/d/cors-unblock) — 6,345 users, 3.74 / 5
- [CORS Everywhere](https://chrome-stats.com/d/cors-everywhere) — 20,823 users, 4.13 / 5
- [CORS Unblock](https://chrome-stats.com/d/cors-unblock-enable-best) — 446 users
- [Moesif Origin & CORS Changer](https://chrome-stats.com/d/moesif-origin-cors-changer1) — 491 users, 3.00 / 5
- [CORS for Me](https://chrome-stats.com/d/cors-for-me) — 39 users
- [CORS dev tool](https://chrome-stats.com/d/cors-dev-tool) — 13 users, 3.67 / 5
- [CORS Unbound](https://chrome-stats.com/d/cors-unbound) — 20 users
- [CORS Unlocker](https://chrome-stats.com/d/cors-unlocker) — 19 users
- [cors-plugin](https://chrome-stats.com/d/cors-plugin) — 130 users, 3.75 / 5
- [CORS Unblock](https://chrome-stats.com/d/cors-unblock2) — 89 users, 5.00 / 5
- [Custom CORS Control](https://chrome-stats.com/d/custom-cors-control) — 6 users
- [Cross Domain - CORS](https://chrome-stats.com/d/cross-domain-cors) — 1,018 users, 2.71 / 5

---

Source: [Chrome-Stats](https://chrome-stats.com/d/access-control-allow-origin)
