TLS Lens by Marco Appoldt
TLS Lens explains in plain language how secure your connection to the current website is: who issued the certificate, how long it remains valid and whether anything looks wrong. Technical details stay one click away.
27 Users27 Users
Extension Metadata
Screenshots
About this extension
TLS Lens shows you in one click where your connection to the current website stands — without going through Firefox's page information dialog.
Understandable for everyone
• A single plain sentence sums up the situation: who issued the certificate, which domain it covers and how long it remains valid.
• The remaining lifetime is spelled out in days, colour-coded from green through amber to red.
• Every technical term is explained in one sentence — just hover over it.
• A coloured banner tells you immediately whether the connection is secure, weak or broken.
Warns you when something is off
TLS Lens reports in plain language when a connection is outdated or insecurely configured:
• outdated TLS versions (TLS 1.0 and 1.1)
• weak encryption methods
• certificates signed with SHA-1 or MD5
• keys that are too short
• insufficient entries in the Certificate Transparency logs
• certificates about to expire
It also detects expired certificates, domain mismatches and untrusted issuers. On certificate errors the toolbar icon turns red. Well-configured sites show no warnings at all — the view stays calm.
For those who want the details
Collapsed by default, so the standard view stays uncluttered:
• TLS version, cipher suite, Extended Validation (EV), Certificate Transparency and OCSP
• common name (CN), issuer with organisation and CN, validity period
• Subject Alternative Names (SAN) — every domain and IP address the certificate covers
• Authority Information Access (AIA) with OCSP and CA Issuers URLs
• the complete certificate chain as a tree, up to the trusted root
• technical details: SHA-256 fingerprint, serial number, public key algorithm and size, signature algorithm, key usage
Handy in daily use
• Copy a report or the certificate as PEM to the clipboard in one click — for support tickets and documentation.
• Light and dark theme: follows your system or can be set manually.
• German and English, switchable at any time from the settings menu.
Privacy
TLS Lens collects and transmits no data. The extension makes no network requests of its own: it only reads what the browser has already verified for the connection you are on. Everything stays in memory and is discarded as soon as the tab closes.
Please note
Certificate data can only be captured while a page is loading. Tabs that were already open before you installed the extension therefore show nothing yet — one click on "Reload page" in the popup is enough.
Open source under the Mozilla Public License 2.0.
This release makes TLS Lens usable without prior knowledge:
• New: plain-language summary — one sentence explaining who issued the certificate, for which domain and how long it remains valid.
• New: remaining lifetime in days with traffic-light colouring.
• New: warnings for outdated TLS versions, weak cipher suites, SHA-1 or MD5 signatures, short keys, insufficient Certificate Transparency and imminent expiry.
• New: explanatory tooltips on every technical term.
• New: collapsible technical details with SHA-256 fingerprint, serial number, issue date, public key algorithm and size, signature algorithm and key usage.
• New: light and dark theme, optionally following the system.
• New: copy a report or the certificate as PEM to the clipboard.
• Fixed: TLS 1.0 was displayed as "TLS 1".
• Fixed: the day count was off by one for expired certificates.
• Fixed: on a domain mismatch the banner still reported a secure connection.
Understandable for everyone
• A single plain sentence sums up the situation: who issued the certificate, which domain it covers and how long it remains valid.
• The remaining lifetime is spelled out in days, colour-coded from green through amber to red.
• Every technical term is explained in one sentence — just hover over it.
• A coloured banner tells you immediately whether the connection is secure, weak or broken.
Warns you when something is off
TLS Lens reports in plain language when a connection is outdated or insecurely configured:
• outdated TLS versions (TLS 1.0 and 1.1)
• weak encryption methods
• certificates signed with SHA-1 or MD5
• keys that are too short
• insufficient entries in the Certificate Transparency logs
• certificates about to expire
It also detects expired certificates, domain mismatches and untrusted issuers. On certificate errors the toolbar icon turns red. Well-configured sites show no warnings at all — the view stays calm.
For those who want the details
Collapsed by default, so the standard view stays uncluttered:
• TLS version, cipher suite, Extended Validation (EV), Certificate Transparency and OCSP
• common name (CN), issuer with organisation and CN, validity period
• Subject Alternative Names (SAN) — every domain and IP address the certificate covers
• Authority Information Access (AIA) with OCSP and CA Issuers URLs
• the complete certificate chain as a tree, up to the trusted root
• technical details: SHA-256 fingerprint, serial number, public key algorithm and size, signature algorithm, key usage
Handy in daily use
• Copy a report or the certificate as PEM to the clipboard in one click — for support tickets and documentation.
• Light and dark theme: follows your system or can be set manually.
• German and English, switchable at any time from the settings menu.
Privacy
TLS Lens collects and transmits no data. The extension makes no network requests of its own: it only reads what the browser has already verified for the connection you are on. Everything stays in memory and is discarded as soon as the tab closes.
Please note
Certificate data can only be captured while a page is loading. Tabs that were already open before you installed the extension therefore show nothing yet — one click on "Reload page" in the popup is enough.
Open source under the Mozilla Public License 2.0.
This release makes TLS Lens usable without prior knowledge:
• New: plain-language summary — one sentence explaining who issued the certificate, for which domain and how long it remains valid.
• New: remaining lifetime in days with traffic-light colouring.
• New: warnings for outdated TLS versions, weak cipher suites, SHA-1 or MD5 signatures, short keys, insufficient Certificate Transparency and imminent expiry.
• New: explanatory tooltips on every technical term.
• New: collapsible technical details with SHA-256 fingerprint, serial number, issue date, public key algorithm and size, signature algorithm and key usage.
• New: light and dark theme, optionally following the system.
• New: copy a report or the certificate as PEM to the clipboard.
• Fixed: TLS 1.0 was displayed as "TLS 1".
• Fixed: the day count was off by one for expired certificates.
• Fixed: on a domain mismatch the banner still reported a secure connection.
Rated 4.3 by 3 reviewers
Permissions and data
Required permissions:
- Input data to the clipboard
- Access your data for all websites
Data collection:
- The developer says this extension doesn't require data collection.
More information
- Add-on Links
- Version
- 1.4
- Size
- 61.98 KB
- Last updated
- 10 days ago (Aug 19, 2026)
- Related Categories
- License
- Mozilla Public License 2.0
- Version History
- Add to collection