Security

Content Security Policy Analyzer

Review a pasted Content-Security-Policy header and inspect its directive and source list.

How this tool works

CSP restricts resource sources by directive. Duplicate directives and broad sources can make a policy difficult to reason about, so this tool surfaces them for human review.

A static report cannot prove a site secure or predict every browser behavior. Report-only policy does not enforce blocking.

Examples

  • Find unsafe-inline in script-src.
  • Notice a wildcard source.
  • Identify duplicate directives.

Common use cases

Review a proposed policy before testing it in the browser.

Worked synthetic example

Valid example

script-src 'self' 'unsafe-inline'

Expected: script-src sources and an unsafe-inline warning. The warning points to a broad script policy, not a measured exploit.

Failure or warning to recognize

Warning / interpretation

script-src 'unsafe-inline' *; script-src 'self'

Expected: A wildcard or duplicate directive is listed as a finding; static inspection cannot establish enforcement or overall security.

Related guides

Official references

Related tools

Content Security Policy Analyzer: Review CSP directives and risky sources | DevPouch