CSP Header Analyzer
Paste a Content-Security-Policy header value to check it for unsafe directives, missing hardening, and deprecated syntax. Nothing is sent to a server.
Paste just the header value (everything after Content-Security-Policy:). Start from a template and edit it, or paste your own header to audit it.
- info
No report-uri or report-to set — violation reports aren't collected, so silent breakage or attempted attacks go unnoticed.
About this tool
CSP Header Analyzer
This tool parses a Content-Security-Policy header value into its individual directives and checks each one against a set of known-risky patterns: 'unsafe-inline' and 'unsafe-eval' in script-src, wildcard (*) sources, missing object-src or base-uri, absent frame-ancestors, and directives with no violation reporting configured.
It also flags duplicate directives (browsers only honor the first occurrence of a fetch directive) and deprecated directives like block-all-mixed-content that current browsers silently ignore.
Two starting templates are included — a strict baseline with no unsafe- keywords, and a looser report-only starting point for policies being rolled out gradually. Both can be edited directly in the textarea.
Header-checker sites will grade a policy for you, but a grade is not an explanation — 'C grade, 3 warnings' doesn't tell you which directive to fix first or why the fix won't break your app. This analyzer reports every finding with the reasoning attached: why unsafe-inline undoes script protection, why a missing object-src lets a plugin-based escape through, why duplicate directives silently no-op. It's built for the iterate loop — paste, fix one directive, paste again — entirely client-side, so it works for internal admin panels and unannounced deployments you'd rather not fetch from a third-party scanner.
When to use it
Review a CSP before shipping it
Paste the header your app is about to send and fix every error/warning before it goes to production.
Audit a live site's policy
Copy the Content-Security-Policy value from a site's response headers (DevTools → Network) and paste it in to see what it actually restricts.
Start a new policy from scratch
Load the strict baseline template, then loosen individual directives only as far as your app's assets require.
Questions
Does this check the live headers of a URL?
No — this tool only analyzes a header value you paste in. It doesn't fetch anything, by design, so it works entirely offline.
Why is 'unsafe-inline' flagged as an error?
'unsafe-inline' allows any inline <script> tag to execute, which removes most of what CSP protects against for cross-site scripting. A nonce or hash-based allowlist achieves the same functionality safely.
What does 'directive appears more than once' mean?
For fetch directives (script-src, style-src, etc.), browsers only apply the first occurrence in a single CSP header and silently ignore any repeats of the same directive name — a common source of policies that don't do what their author expects.
What is a good Content-Security-Policy to start with?
Start from the strict template built into the tool: default-src 'self', explicit script-src with no unsafe- keywords, object-src 'none', base-uri 'none', frame-ancestors 'none' unless you frame content, and a report-to endpoint. Loosen only the directives your app's assets actually require, one at a time, watching the browser console for violations as you go.
How do I find a site's CSP header?
Open DevTools → Network, reload, select the document request, and read the Content-Security-Policy response header — or run curl -sI https://example.com | grep -i content-security-policy in a terminal. Copy the whole header value (it's one long string, even when it spans lines) and paste it here.
Does CSP replace escaping output or sanitizing input?
No. CSP is a second line of defense that limits what injected script can do; it does not fix the injection itself. Treat it as a blast-radius control layered on top of proper output encoding and input validation — a strong CSP with an XSS hole still leaks, just less catastrophically.
Related resources