Content Security Policy Analyzer
Break a Content-Security-Policy header into its directives and highlight weaknesses such as unsafe-inline, unsafe-eval, wildcard sources and a missing default-src.
About the Content Security Policy Analyzer
Break a Content-Security-Policy header into its directives and highlight weaknesses such as unsafe-inline, unsafe-eval, wildcard sources and a missing default-src.
Queries run from our global edge network, so you see what a neutral observer on the public internet sees — not what your local network or ISP resolver happens to have cached.
Frequently asked questions
What does the Content Security Policy Analyzer do?
Break a Content-Security-Policy header into its directives and highlight weaknesses such as unsafe-inline, unsafe-eval, wildcard sources and a missing default-src.
Is the Content Security Policy Analyzer free to use?
Yes. The Content Security Policy Analyzer is completely free with no account, no signup and no usage limits for normal use.
Do you log the lookups I run?
No. Queries are processed at the edge and returned straight to you. We do not retain, profile or sell your lookup history.