Security Tools

CSP Analyzer

Find the weak spots in a Content-Security-Policy. Paste a policy or enter a URL and the analyzer reads the header (or a meta tag), parses every directive and checks it against CSP Level 3 and strict-CSP guidance: unsafe-inline without nonces, unsafe-eval, wildcard and scheme sources, host allow-lists that are often bypassable, missing object-src, base-uri, frame-ancestors and form-action, deprecated directives, reporting, report-only mode and meta-tag limitations.

  • Encrypted connection
  • No sign-up
  • Free to use

A URL is fetched once by our server (header and meta tag); a pasted policy is analysed in your browser only.

How to use CSP Analyzer

  1. Paste a policy or enter a URL.
  2. Click Analyze CSP.
  3. Read each finding.
  4. Tighten the policy and test in report-only mode.

CSP Analyzer features

Score and grade

From rule-based findings.

Directive table

Every directive and its sources.

Strict CSP

Nonces, hashes and strict-dynamic.

Report-only detection

Warns that nothing is blocked yet.

Meta tag limits

frame-ancestors and reporting.

Paste mode

Never leaves your browser.

When to use CSP Analyzer

  • Hardening a web application.
  • Reviewing a policy before deployment.
  • Security code review.
  • Learning CSP.

CSP Analyzer FAQ

What is the most important CSP rule?

Do not allow inline scripts without nonces or hashes – that is what stops most cross-site scripting.

Why are host allow-lists weak?

Allowed hosts often serve JSONP endpoints or user-uploaded scripts that attackers can abuse. Nonces with strict-dynamic avoid this.

What does report-only do?

It reports violations without blocking, so you can test a policy safely.

Can CSP be set in a meta tag?

Yes, but frame-ancestors, sandbox and reporting do not work there.

From permissive to strict

Start with report-only, collect violation reports, replace inline scripts with nonces or external files, and switch to enforcing when the reports are clean.

How it works: checks that need the network are made by our server through a guarded client that only connects to public addresses on the standard web ports, pins every connection to the validated address and limits time and response size. Pasted input is analysed in your browser and never sent. Nothing you check is stored, and requests are rate-limited to keep the service fair.

Every finding is rule-based and explained: the tool tells you what it saw, why it matters and what to change, instead of showing an unexplained score. Grades summarise the findings so you can compare sites and track progress after a fix, but the individual checks are what you should act on.

Only check systems you own or are authorised to assess. The probes behave like a normal browser or client – they read public responses and perform ordinary handshakes – and never try to exploit a weakness, guess passwords or overload a server.

Related tools on this site cover the rest of a security review – security header generators, CSP and CORS generators, SSL certificate and expiry checks, SPF, DKIM and DMARC record checkers, JWT tools and password generators – so you can fix what you find in the same place.

Who it is for: developers hardening a release, system administrators and DevOps teams, security and compliance reviewers preparing for audits such as PCI DSS or ISO 27001, and site owners who want to know whether their basics are right. No account or installation is needed.

Other useful tools