Runs entirely in your browser — nothing you type is sent to our servers.

About this tool

Paste a Content-Security-Policy or load it from a URL. The analyzer lists each directive and flags common weaknesses such as unsafe-inline, unsafe-eval, wildcards and missing base-uri or object-src.

Related tools