CSP analyzer
Read a Content Security Policy more clearly.
Separate directives and flag common structural gaps, duplicated rules, wildcards, unsafe script modes, and insecure source schemes—all locally.
Parsed directives
Findings
Deploy in report-only mode first
For an existing application, collect violation reports and inventory legitimate sources before enforcing a new policy. Prefer nonces or hashes for necessary inline scripts, constrain plugins and base URLs, and control which origins can frame or receive form submissions.