Security
Content Security Policy Analyzer
Review a pasted Content-Security-Policy header and inspect its directive and source list.
How this tool works
CSP restricts resource sources by directive. Duplicate directives and broad sources can make a policy difficult to reason about, so this tool surfaces them for human review.
A static report cannot prove a site secure or predict every browser behavior. Report-only policy does not enforce blocking.
Examples
- Find unsafe-inline in script-src.
- Notice a wildcard source.
- Identify duplicate directives.
Common use cases
Worked synthetic example
Valid example
script-src 'self' 'unsafe-inline'
Expected: script-src sources and an unsafe-inline warning. The warning points to a broad script policy, not a measured exploit.
Failure or warning to recognize
Warning / interpretation
script-src 'unsafe-inline' *; script-src 'self'
Expected: A wildcard or duplicate directive is listed as a finding; static inspection cannot establish enforcement or overall security.