Manage insecure HTTP and WebSocket connections before sensitive data is transmitted over an unencrypted channel.
Modern browsers (Chrome, Edge, Safari) still natively permit unencrypted fallback connections across legacy protocols including standard HTTP, FTP, and unencrypted WebSockets (ws://). These unencrypted streams leak sensitive payload data—such as authentication tokens, session cookies, and user history—to any adversarial listening device on the local network.
The HTTPS Control Extension helps to manage all of these unwanted connections. The extension upgrades or blocks insecure connections identified by Google's Declarative Net Request API.
Automatically upgrade insecure requests.
Block and inspect remaining insecure requests.
Click the extension icon 🔒 to bypass the block.