Neatbo.

CSP policy inspection

Inspect a pasted CSP policy for malformed source expressions, duplicate directives, broad allowances and missing restrictions.

Browser-local processingInputFile / TextOutputFile / TextUp to 1 MiB per file · File limit: 1
  1. 1Add input
  2. 2Review and run
  3. 3Get your result

Tool input and files are processed in this browser without being uploaded.

Your input

Inputs are kept temporarily in this tab when switching tools. Refreshing or closing clears them; large results may need to be regenerated.

⌘ / Ctrl + Enter to run
CSP input source
0 characters · 0 bytes
Preparing the tool…

Before you start

Paste one Content-Security-Policy header value without the header name. Check common source-list syntax, including malformed wildcard hosts, plus duplicate directives and broad allowances.

How to use this tool

  1. Paste the CSP header value without the header name.
  2. Review invalid source expressions, including misplaced wildcards, duplicate directives, broad permissions and common missing restrictions.
  3. Download the complete JSON report; verify changes with report-only mode and browser diagnostics on the actual site.

Supported inputs and limits

Local review of one policy only. Common source-list syntax is checked, but the full CSP grammar, browser support, multiple headers and report-only behavior require browser testing; findings are not a security certification.

Files and input stay in the browser. One pasted value or UTF-8 .txt file is limited to 1 MiB. Outputs do not overwrite original files.

Worked example

Example input

default-src 'self'; script-src 'self' 'unsafe-eval'; object-src 'none'
Example options
{}

Example output

{
  "directives": {
    "default-src": [
      "'self'"
    ],
    "script-src": [
      "'self'",
      "'unsafe-eval'"
    ],
    "object-src": [
      "'none'"
    ]
  },
  "duplicates": [],
  "findings": [
    {
      "directive": "script-src",
      "finding": "unsafe-eval allows string code evaluation"
    },
    {
      "directive": "base-uri",
      "finding": "Missing explicit directive; default-src does not supply this restriction"
    },
    {
      "directive": "frame-ancestors",
      "finding": "Missing explicit directive; default-src does not supply this restriction"
    }
  ],
  "browserEnforcementChecked": false
}

When something does not work

Correct the named source expression or duplicate directive, then inspect the policy again. Confirm the server actually sends the updated header and test it in the browser.

Frequently asked questions

Which CSP settings are flagged?

Common source-list syntax is checked. For example, *.example.com* is flagged because a host wildcard belongs at the start, not the end. Duplicate directives, broad allowances and missing restrictions are also shown.

What should the example produce?

unsafe-eval should be flagged. Verify whether base-uri and frame-ancestors should be supplied explicitly for your app.

Which cases are outside its scope?

This checks one pasted policy locally. It does not validate the full CSP grammar or fetch your site's response; multiple policies, nonce/hash behavior and browser enforcement need testing on the actual site.

Documentation & further reading

Related tools