CSP Evaluator
Analyze a Content Security Policy and identify potentially unsafe directives, weak configurations and common security issues.
What is CSP Evaluator?
Analyze a Content Security Policy and identify configuration problems that can weaken browser security. Paste a CSP header or policy and review its directives, sources and potential security issues.
How to use
- Paste a Content Security Policy.
- Parse the CSP directives and source expressions.
- Review detected configuration issues.
- Inspect warnings for potentially unsafe directives.
- Adjust the policy and evaluate it again.
Features
- CSP policy parsing
- Directive detection
- Source expression analysis
- Unsafe directive detection
- Wildcard source detection
- Unsafe-inline detection
- Unsafe-eval detection
- Policy warnings
- Security recommendations
Common Use Cases
- Auditing Content Security Policy
- Improving website security
- Debugging CSP configuration
- Reviewing HTTP security headers
- Preparing CSP policies for production
- Learning CSP security rules
Example
default-src 'self'; script-src 'self' 'unsafe-inline' https://cdn.example.com; img-src * data:;
Findings: 2 Warning: script-src contains 'unsafe-inline' Warning: img-src allows all sources with * Recommendation: Restrict script and image sources where possible.
FAQ
What is CSP?
Content Security Policy is a browser security mechanism that restricts which resources a web page can load and which types of content the browser is allowed to execute.
What does CSP Evaluator check?
The evaluator parses CSP directives and checks for potentially weak configurations such as unrestricted wildcards, unsafe-inline and unsafe-eval.
Is 'unsafe-inline' dangerous?
It can significantly weaken protection against certain script injection attacks because it permits inline scripts or styles where otherwise they could be blocked by the policy.
Is allowing * in a CSP dangerous?
A wildcard can allow resources from a much broader set of origins than necessary. The security impact depends on which directive uses it and what types of resources are being allowed.
Does CSP Evaluator guarantee that a policy is secure?
No. Automated analysis can identify common weaknesses, but a secure CSP also depends on the application's architecture, resources and intended behavior.
Does the evaluator modify my website's CSP?
No. It only analyzes the policy you provide and reports potential issues and recommendations.
Missing a feature?
If this tool doesn't cover your use case or is missing functionality, please let me know through the Contact page.
New improvements and features are added based on user feedback.