Skip to content
FlexibleToolsAI
Security Toolkit · Free, Nothing Stored

CSP Evaluator

Find out whether your Content-Security-Policy actually stops XSS. Paste a policy or fetch it from a URL, and the evaluator flags high-severity issues ('unsafe-inline' scripts, wildcards, bypassable CDN allowlists), missing directives (object-src, base-uri, frame-ancestors) and deprecated syntax.

Paste the policy or enter a URL to fetch its header. The evaluator parses each directive and applies checks based on Google's CSP Evaluator research: script sources that allow injection or JSONP/AngularJS bypasses, missing object-src 'none' and base-uri, and report-only mode. It shows the parsed directives and what to fix.

Checks follow the research behind Google's CSP Evaluator: allowlist policies are often bypassable, so the most robust setup is a strict CSP with nonces or hashes plus 'strict-dynamic', object-src 'none' and base-uri 'self'.

Instant Results

Live checks in seconds

Nothing Stored

No logs of what you check

No Sign-Up

Free, no credits or email

Suggest a Feature or Improvement for CSP Evaluator

Need custom options, higher limits, or extra format support? Let our engineering team know!

How to use CSP Evaluator

  1. 1Paste the policy, or fetch it from a URL.
  2. 2Review high-severity findings first.
  3. 3Apply the suggested fixes.
  4. 4Re-evaluate until only informational notes remain.

Common CSP weaknesses

'unsafe-inline' in script-src allows any injected script unless a nonce or hash is present. Wildcards, https:, data: and blob: let attackers load script from anywhere. Allowlisting large CDNs (cdnjs, jsDelivr, googleapis) is risky because they host code that can be abused. Missing object-src and base-uri leave classic bypasses open.

A policy with nonces or hashes plus 'strict-dynamic' avoids most of these.

Next steps

Generate a stronger policy with the CSP Header Generator and check your other headers with the Security Headers Checker.

Frequently Asked Questions

Is this the same as Google's CSP Evaluator?

It applies the same core checks from Google's research, explained in plain English. Google's tool remains a good second opinion.

Does it check CSP in meta tags?

When fetching a URL it reads the HTTP header. Paste a meta-tag policy directly to evaluate it.

What do you do with the domains and URLs I check?

Our server performs the lookup once and returns the result to your browser. We don't store the addresses you check or build a history. Private and internal addresses are blocked.

Guides & Tutorials

Related Tools