CSP analyzer

Read a Content Security Policy more clearly.

Separate directives and flag common structural gaps, duplicated rules, wildcards, unsafe script modes, and insecure source schemes—all locally.

Parsed directives

Findings

Deploy in report-only mode first

For an existing application, collect violation reports and inventory legitimate sources before enforcing a new policy. Prefer nonces or hashes for necessary inline scripts, constrain plugins and base URLs, and control which origins can frame or receive form submissions.