CSP Evaluator
Find out whether your Content-Security-Policy actually stops XSS. Paste a policy or fetch it from a URL, and the evaluator flags high-severity issues ('unsafe-inline' scripts, wildcards, bypassable CDN allowlists), missing directives (object-src, base-uri, frame-ancestors) and deprecated syntax.
Paste the policy or enter a URL to fetch its header. The evaluator parses each directive and applies checks based on Google's CSP Evaluator research: script sources that allow injection or JSONP/AngularJS bypasses, missing object-src 'none' and base-uri, and report-only mode. It shows the parsed directives and what to fix.
Instant Results
Live checks in seconds
Nothing Stored
No logs of what you check
No Sign-Up
Free, no credits or email
Suggest a Feature or Improvement for CSP Evaluator
Need custom options, higher limits, or extra format support? Let our engineering team know!
How to use CSP Evaluator
- 1Paste the policy, or fetch it from a URL.
- 2Review high-severity findings first.
- 3Apply the suggested fixes.
- 4Re-evaluate until only informational notes remain.
Common CSP weaknesses
'unsafe-inline' in script-src allows any injected script unless a nonce or hash is present. Wildcards, https:, data: and blob: let attackers load script from anywhere. Allowlisting large CDNs (cdnjs, jsDelivr, googleapis) is risky because they host code that can be abused. Missing object-src and base-uri leave classic bypasses open.
A policy with nonces or hashes plus 'strict-dynamic' avoids most of these.
Next steps
Generate a stronger policy with the CSP Header Generator and check your other headers with the Security Headers Checker.
Frequently Asked Questions
Is this the same as Google's CSP Evaluator?
It applies the same core checks from Google's research, explained in plain English. Google's tool remains a good second opinion.
Does it check CSP in meta tags?
When fetching a URL it reads the HTTP header. Paste a meta-tag policy directly to evaluate it.
What do you do with the domains and URLs I check?
Our server performs the lookup once and returns the result to your browser. We don't store the addresses you check or build a history. Private and internal addresses are blocked.
Guides & Tutorials
Related Tools
CSP Header Generator
Build a Content-Security-Policy — strict nonce-based or allowlist — for any server or framework.
Security Headers Checker
Scan any website's HTTP security headers and get an A+ to F grade with fixes.
CORS Checker
Test an endpoint's CORS policy with any Origin and a real preflight — find dangerous misconfigurations.