CSP?

CSP Header Analyzer

Parse an existing Content-Security-Policy and flag wildcard, unsafe, insecure, duplicate, and missing controls

Security & Auth
πŸ”’ 100% client-side β€” your data never leaves this page
Maintained by Evanβ€’Updated: September 30, 2026
CSP HEADER
FINDINGS

Policy findings will appear here.

About this tool

Parse one CSP or Report-Only policy and review a limited set of source-list patterns. Duplicate directives remain visible but checks use the first occurrence, matching CSP parsing. Findings are local review prompts for wildcard, unsafe keywords, HTTP sources and explicit baseline controls. This is not a browser policy evaluator, and a finding count is not a security score.

Scenario Recipes

01

Prepare a CSP tightening change with Report-Only evidence

Goal: Use static findings as a review input rather than a security verdict

  1. Analyze the current enforced policy and classify every high or medium finding by application dependency.
  2. Draft the narrower policy with the CSP generator and deploy it as Report-Only to representative routes.
  3. Review browser violation reports, fix required sources, test authentication and payment flows, then enforce through normal change control.

Result: A CSP change backed by static review, runtime evidence, and route-level testing.

Frequently Asked Questions

Which duplicate directive takes effect?

Within one policy, the first occurrence is used and later duplicates are ignored. The table labels ignored rows; source warnings and baseline checks are based on the first value.

Can I paste several CSP headers or comma-separated policies?

Not together. This tool accepts one policy at a time and rejects a policy list. Browsers enforce multiple policies together; merging their source lists into one would change the meaning.

Does Report-Only block unsafe content?

No. A Report-Only header reports violations without enforcing blocking. This page recognizes the prefix but does not deploy a policy, send reports or inspect runtime violations.

Are unsafe-inline and missing object-src always vulnerabilities?

No. Nonces, hashes, directive fallback, strict-dynamic and the application context affect behavior. The explicit object-src recommendation does not evaluate default-src inheritance. Review each textual finding in the actual browser and application.

What does the analyzer leave out?

It does not validate nonce/hash bytes, source trust, every directive grammar, redirects, report endpoints or browser compatibility. Unknown names may be newer, obsolete or misspelled. Processing is local and editing the policy clears previous findings.

Keep browsing