CSP policy inspection
Inspect a pasted CSP policy for malformed source expressions, duplicate directives, broad allowances and missing restrictions.
- 1Add input
- 2Review and run
- 3Get your result
Tool input and files are processed in this browser without being uploaded.
Before you start
Paste one Content-Security-Policy header value without the header name. Check common source-list syntax, including malformed wildcard hosts, plus duplicate directives and broad allowances.
How to use this tool
- Paste the CSP header value without the header name.
- Review invalid source expressions, including misplaced wildcards, duplicate directives, broad permissions and common missing restrictions.
- Download the complete JSON report; verify changes with report-only mode and browser diagnostics on the actual site.
Supported inputs and limits
Local review of one policy only. Common source-list syntax is checked, but the full CSP grammar, browser support, multiple headers and report-only behavior require browser testing; findings are not a security certification.
Files and input stay in the browser. One pasted value or UTF-8 .txt file is limited to 1 MiB. Outputs do not overwrite original files.
Worked example
Example input
default-src 'self'; script-src 'self' 'unsafe-eval'; object-src 'none'
Example options
{}Example output
{
"directives": {
"default-src": [
"'self'"
],
"script-src": [
"'self'",
"'unsafe-eval'"
],
"object-src": [
"'none'"
]
},
"duplicates": [],
"findings": [
{
"directive": "script-src",
"finding": "unsafe-eval allows string code evaluation"
},
{
"directive": "base-uri",
"finding": "Missing explicit directive; default-src does not supply this restriction"
},
{
"directive": "frame-ancestors",
"finding": "Missing explicit directive; default-src does not supply this restriction"
}
],
"browserEnforcementChecked": false
}When something does not work
Correct the named source expression or duplicate directive, then inspect the policy again. Confirm the server actually sends the updated header and test it in the browser.
Frequently asked questions
Which CSP settings are flagged?
Common source-list syntax is checked. For example, *.example.com* is flagged because a host wildcard belongs at the start, not the end. Duplicate directives, broad allowances and missing restrictions are also shown.
What should the example produce?
unsafe-eval should be flagged. Verify whether base-uri and frame-ancestors should be supplied explicitly for your app.
Which cases are outside its scope?
This checks one pasted policy locally. It does not validate the full CSP grammar or fetch your site's response; multiple policies, nonce/hash behavior and browser enforcement need testing on the actual site.
Documentation & further reading
Related tools
QR code maker
Turn a link or a little text into a QR code.
UTM link builder
Add your campaign details without the guesswork.
Meta tags generator
Fill in page details and copy the resulting meta tags.
robots.txt generator
Build a robots.txt file from the crawl rules you choose.