Ctrl + K
Home›Security Tools›CSP Evaluator
Free Developer Tool

CSP Evaluator

Analyze a Content Security Policy and identify potentially unsafe directives, weak configurations and common security issues.

What is CSP Evaluator?

Analyze a Content Security Policy and identify configuration problems that can weaken browser security. Paste a CSP header or policy and review its directives, sources and potential security issues.

How to use

  1. Paste a Content Security Policy.
  2. Parse the CSP directives and source expressions.
  3. Review detected configuration issues.
  4. Inspect warnings for potentially unsafe directives.
  5. Adjust the policy and evaluate it again.

Features

  • CSP policy parsing
  • Directive detection
  • Source expression analysis
  • Unsafe directive detection
  • Wildcard source detection
  • Unsafe-inline detection
  • Unsafe-eval detection
  • Policy warnings
  • Security recommendations

Common Use Cases

  • Auditing Content Security Policy
  • Improving website security
  • Debugging CSP configuration
  • Reviewing HTTP security headers
  • Preparing CSP policies for production
  • Learning CSP security rules

Example

Input
default-src 'self'; script-src 'self' 'unsafe-inline' https://cdn.example.com; img-src * data:;
Output
Findings: 2

Warning: script-src contains 'unsafe-inline'
Warning: img-src allows all sources with *

Recommendation: Restrict script and image sources where possible.

FAQ

What is CSP?

Content Security Policy is a browser security mechanism that restricts which resources a web page can load and which types of content the browser is allowed to execute.

What does CSP Evaluator check?

The evaluator parses CSP directives and checks for potentially weak configurations such as unrestricted wildcards, unsafe-inline and unsafe-eval.

Is 'unsafe-inline' dangerous?

It can significantly weaken protection against certain script injection attacks because it permits inline scripts or styles where otherwise they could be blocked by the policy.

Is allowing * in a CSP dangerous?

A wildcard can allow resources from a much broader set of origins than necessary. The security impact depends on which directive uses it and what types of resources are being allowed.

Does CSP Evaluator guarantee that a policy is secure?

No. Automated analysis can identify common weaknesses, but a secure CSP also depends on the application's architecture, resources and intended behavior.

Does the evaluator modify my website's CSP?

No. It only analyzes the policy you provide and reports potential issues and recommendations.