# HeaderForge

> Local-only, open-source HTTP header modifier. No ads, no telemetry, least-privilege.

Canonical page: [https://chrome-stats.com/d/headerforge](https://chrome-stats.com/d/headerforge)

## Overview

- **ID:** `headerforge`
- **Platform:** Firefox
- **Type:** Firefox add-on
- **Status:** Available
- **Publisher:** Andrei Dev
- **Category:** web-development
- **Daily users:** 6
- **Weekly downloads:** 3
- **Version:** 1.3.7
- **Last updated:** 2026-07-28
- **First published:** 2026-07-17
- **Size:** 206 KB
- **Data as of:** 2026-09-08
- **Store listing:** [Firefox Add-ons Store](https://addons.mozilla.org/firefox/addon/headerforge/)
- **Website:** [https://headerforge.dev](https://headerforge.dev/)
- **Privacy policy:** [https://addons.mozilla.org/firefox/addon/headerforge/privacy/](https://addons.mozilla.org/firefox/addon/headerforge/privacy/)

## Description

HeaderForge modifies HTTP headers on the sites you choose. Built for developers, testers and security engineers who need to reshape requests without a proxy.

WHAT IT DOES
• Header rules: add, override or remove request and response headers, grouped into profiles you can switch with one click.
• Precise scope: every rule applies only to the origins you grant. Broad host access is optional and requested by your own action, never at install.
• Safety gate: rules that weaken protective headers (CSP, X-Frame-Options and the like) are flagged and require explicit confirmation before they apply.
• Response mocks: replace or patch fetch/XHR responses to test edge cases without touching the backend.
• Cookie editor: structured editing of the Cookie header instead of hand-typed strings.
• Import/export: share profiles as files; imported files are validated and dangerous rules are re-confirmed.

PRIVATE BY DESIGN
No account, no server, no analytics. Your configuration lives in your browser and nowhere else. The code is open source (MIT).

## Rankings

- #41,658 — Overall
- #82 — forget
- #94 — header

## Permissions and access

### Permissions

- `declarativeNetRequestWithHostAccess`
- `storage`
- `scripting`
- `activeTab`

## Safety

- **Risk impact:** Very low risk impact
- **Risk likelihood:** High risk likelihood

### Analysis details

- This extension has low user count. Unpopular extensions may not be stable or safe.

> Some risk analysis details are omitted from this free response. [Upgrade to view the full analysis](https://chrome-stats.com/pricing).

## Similar extensions and apps

- [Header Forge](https://chrome-stats.com/d/header-forge) — 26 users, 5.00 / 5
- [HeadForge](https://chrome-stats.com/d/headforge) — 1 users
- [NoobHeaders](https://chrome-stats.com/d/noobheaders) — 10 users
- [Overhead — HTTP Header Editor](https://chrome-stats.com/d/overhead-http-header-editor) — 1 users, 5.00 / 5
- [HeaderPilot](https://chrome-stats.com/d/headerpilot) — 1 users
- [DevHeaders - HTTP Header Editor & Modifier](https://chrome-stats.com/d/devheaders) — 2 users
- [Header Override](https://chrome-stats.com/d/header-override) — 38 users
- [HeaderMod](https://chrome-stats.com/d/headermod) — 292 users
- [Header Override](https://chrome-stats.com/d/headeroverride) — 7 users
- [FlexHeaders - Modify HTTP Headers](https://chrome-stats.com/d/flexheaders-alter-http-headers) — 434 users, 5.00 / 5
- [ModHeader By GreatJIN](https://chrome-stats.com/d/modheader-by-greatjin) — 25 users
- [HeaderMod](https://chrome-stats.com/d/headermod-app) — 16 users

---

Source: [Chrome-Stats](https://chrome-stats.com/d/headerforge)
