# CORS Unbound

> Bypass CORS and rewrite HTTP headers directly in the browser, automatically injecting the correct Access-Control-\* headers derived from the browser’s CORS request headers.

Canonical page: [https://chrome-stats.com/d/cors-unbound](https://chrome-stats.com/d/cors-unbound)

## Overview

- **ID:** `cors-unbound`
- **Platform:** Firefox
- **Type:** Firefox add-on
- **Status:** Available
- **Publisher:** yobukodori
- **Category:** web-development
- **Daily users:** 20
- **Weekly downloads:** 10
- **Version:** 1.0.1
- **Last updated:** 2026-04-23
- **First published:** 2026-04-19
- **Size:** 48 KB
- **Data as of:** 2026-09-07
- **Store listing:** [Firefox Add-ons Store](https://addons.mozilla.org/firefox/addon/cors-unbound/)
- **Website:** [https://github.com/yobukodori/cors-unbound](https://github.com/yobukodori/cors-unbound)
- **Privacy policy:** [https://addons.mozilla.org/firefox/addon/cors-unbound/privacy/](https://addons.mozilla.org/firefox/addon/cors-unbound/privacy/)

## Description

<strong>CORS Unbound</strong> is a Firefox extension that bypasses CORS restrictions and rewrites HTTP request/response headers directly inside the browser.
It is designed for <strong>local development</strong>, <strong>prototyping</strong>, <strong>automation</strong>, <strong>scraping</strong>, and <strong>advanced debugging</strong> — all without running a server.

<strong>Features</strong>  

<strong>Automatic CORS Bypass</strong>
Injects the appropriate <code>Access-Control-*</code> headers into responses based on the browser’s own CORS request headers.

<strong>Header Rewriting</strong>
Add, modify, or remove <strong>request</strong> and <strong>response</strong> headers using a rule-based UI.

<strong>Rule System</strong>
Each rule defines:
<ul><li><strong>Origin URLs</strong> (the page making the request)  </li><li><strong>Target URLs</strong> (the request destination)  </li><li><strong>Header Actions</strong> (set/remove)  </li><li><strong>Resource Types</strong> (xmlhttprequest, sub_frame, script, image, websocket, etc.)</li></ul>

Learn more at: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/712c1321a44bbec67ffe5edeb3f34e07684ed236b209353c82b80777858e2574/https%3A//github.com/yobukodori/cors-unbound" rel="nofollow">https://github.com/yobukodori/cors-unbound</a>

## Rankings

- #24,644 — Overall
- #175 — destination
- #196 — scraping
- #203 — course
- #221 — inject

## Permissions and access

### Permissions

- `webRequest`
- `webRequestBlocking`
- `storage`
- `<all_urls>`

## Safety

- **Risk impact:** Moderate risk impact
- **Risk likelihood:** High risk likelihood

### Analysis details

- Allows access to all websites, posing a significant security risk as it can monitor and modify data from any visited site.
- This extension has low user count. Unpopular extensions may not be stable or safe.

> Some risk analysis details are omitted from this free response. [Upgrade to view the full analysis](https://chrome-stats.com/pricing).

## Similar extensions and apps

- [CORS Unlocker](https://chrome-stats.com/d/cors-unlocker) — 20 users
- [CORS Unblock](https://chrome-stats.com/d/cors-unblock2) — 90 users, 5.00 / 5
- [CORS Unblock](https://chrome-stats.com/d/cors-unblock) — 6,503 users, 3.74 / 5
- [CORS Everywhere](https://chrome-stats.com/d/cors-everywhere) — 21,464 users, 4.13 / 5
- [CORS dev tool](https://chrome-stats.com/d/cors-dev-tool) — 14 users, 3.67 / 5
- [CORS Everywhere with referer support](https://chrome-stats.com/d/cors-everywhere-referer) — 1 users
- [Custom CORS Control](https://chrome-stats.com/d/custom-cors-control) — 6 users
- [Moesif Origin & CORS Changer](https://chrome-stats.com/d/moesif-origin-cors-changer1) — 505 users, 3.00 / 5
- [Corsify](https://chrome-stats.com/d/corsify) — 1 users, 3.00 / 5
- [Restfox CORS Helper](https://chrome-stats.com/d/restfox-cors-helper) — 175 users, 5.00 / 5
- [Corser](https://chrome-stats.com/d/corser) — 31 users, 3.00 / 5
- [Hoppscotch Extension for Firefox](https://chrome-stats.com/d/hoppscotch) — 3,548 users, 4.78 / 5

---

Source: [Chrome-Stats](https://chrome-stats.com/d/cors-unbound)
