# TLS Lens

> TLS Lens explains in plain language how secure your connection to the current website is: who issued the certificate, how long it remains valid and whether anything looks wrong. Technical details stay one click away.

Canonical page: [https://chrome-stats.com/d/tls-lens](https://chrome-stats.com/d/tls-lens)

## Overview

- **ID:** `tls-lens`
- **Platform:** Firefox
- **Type:** Firefox add-on
- **Status:** Available
- **Publisher:** Marco Appoldt
- **Category:** privacy-security,appearance
- **Daily users:** 28
- **Weekly downloads:** 2
- **Rating:** 4.33 / 5 (3 ratings)
- **Version:** 1.4
- **Last updated:** 2026-08-19
- **First published:** 2026-02-09
- **Size:** 62 KB
- **Data as of:** 2026-09-07
- **Store listing:** [Firefox Add-ons Store](https://addons.mozilla.org/firefox/addon/tls-lens/)

## Description

TLS Lens shows you in one click where your connection to the current website stands — without going through Firefox's page information dialog.

<strong>Understandable for everyone</strong>

• A single plain sentence sums up the situation: who issued the certificate, which domain it covers and how long it remains valid.
• The remaining lifetime is spelled out in days, colour-coded from green through amber to red.
• Every technical term is explained in one sentence — just hover over it.
• A coloured banner tells you immediately whether the connection is secure, weak or broken.

<strong>Warns you when something is off</strong>

TLS Lens reports in plain language when a connection is outdated or insecurely configured:

• outdated TLS versions (TLS 1.0 and 1.1)
• weak encryption methods
• certificates signed with SHA-1 or MD5
• keys that are too short
• insufficient entries in the Certificate Transparency logs
• certificates about to expire

It also detects expired certificates, domain mismatches and untrusted issuers. On certificate errors the toolbar icon turns red. Well-configured sites show no warnings at all — the view stays calm.

<strong>For those who want the details</strong>

Collapsed by default, so the standard view stays uncluttered:

• TLS version, cipher suite, Extended Validation (EV), Certificate Transparency and OCSP
• common name (CN), issuer with organisation and CN, validity period
• Subject Alternative Names (SAN) — every domain and IP address the certificate covers
• Authority Information Access (AIA) with OCSP and CA Issuers URLs
• the complete certificate chain as a tree, up to the trusted root
• technical details: SHA-256 fingerprint, serial number, public key algorithm and size, signature algorithm, key usage

<strong>Handy in daily use</strong>

• Copy a report or the certificate as PEM to the clipboard in one click — for support tickets and documentation.
• Light and dark theme: follows your system or can be set manually.
• German and English, switchable at any time from the settings menu.

<strong>Privacy</strong>

TLS Lens collects and transmits no data. The extension makes no network requests of its own: it only reads what the browser has already verified for the connection you are on. Everything stays in memory and is discarded as soon as the tab closes.

<strong>Please note</strong>

Certificate data can only be captured while a page is loading. Tabs that were already open before you installed the extension therefore show nothing yet — one click on "Reload page" in the popup is enough.

Open source under the Mozilla Public License 2.0.

This release makes TLS Lens usable without prior knowledge:

• New: plain-language summary — one sentence explaining who issued the certificate, for which domain and how long it remains valid.
• New: remaining lifetime in days with traffic-light colouring.
• New: warnings for outdated TLS versions, weak cipher suites, SHA-1 or MD5 signatures, short keys, insufficient Certificate Transparency and imminent expiry.
• New: explanatory tooltips on every technical term.
• New: collapsible technical details with SHA-256 fingerprint, serial number, issue date, public key algorithm and size, signature algorithm and key usage.
• New: light and dark theme, optionally following the system.
• New: copy a report or the certificate as PEM to the clipboard.
• Fixed: TLS 1.0 was displayed as "TLS 1".
• Fixed: the day count was off by one for expired certificates.
• Fixed: on a domain mismatch the banner still reported a secure connection.

## Rankings

- #21,003 — Overall
- #153 — algorithm

## Permissions and access

### Permissions

- `webRequest`
- `webRequestBlocking`
- `storage`
- `clipboardWrite`
- `<all_urls>`

## Safety

- **Risk impact:** High risk impact
- **Risk likelihood:** Moderate risk likelihood

### Analysis details

- Allows access to all websites, posing a significant security risk as it can monitor and modify data from any visited site.
- This extension was recently updated in the past month. New updates may not be stable or safe.

> Some risk analysis details are omitted from this free response. [Upgrade to view the full analysis](https://chrome-stats.com/pricing).

## Similar extensions and apps

- [SSLeuth](https://chrome-stats.com/d/ssleuth) — 65 users
- [IndicateTLS](https://chrome-stats.com/d/indicatetls) — 1,332 users, 4.76 / 5
- [Know TLS Cert](https://chrome-stats.com/d/know-tls-cert) — 3 users
- [InfraLens - Security & Inspector](https://chrome-stats.com/d/infralens-security-inspector) — 1 users
- [Certificate Trust](https://chrome-stats.com/d/certificate-trust) — 120 users, 4.00 / 5
- [cerdicator](https://chrome-stats.com/d/cerdicator) — 1 users
- [Indicate TLS Premium](https://chrome-stats.com/d/indicate-tls-premium) — 1 users
- [LeakLens - Privacy Inspector](https://chrome-stats.com/d/leaklens) — 10 users
- [Certage](https://chrome-stats.com/d/certage) — 25 users
- [SSL Server Test](https://chrome-stats.com/d/qualys-ssl-server-test) — 234 users, 4.00 / 5
- [TrustedSite](https://chrome-stats.com/d/trustedsite) — 14 users
- [SSL Certificate Checker sp](https://chrome-stats.com/d/ssl-certificate-checker-sp) — 16 users

---

Source: [Chrome-Stats](https://chrome-stats.com/d/tls-lens)
