How to use it
- 1
Enter a public http/https URL.
- 2
Run CSP response-header and static-meta parsing.
- 3
Review risky sources, missing directives, and meta-policy limits.
What the tool can do
- Parses enforced CSP, Report-Only, and meta CSP.
- Shows directives, values, and duplicate directives.
- Flags unsafe-inline, unsafe-eval, wildcard, and missing key directives.
Common use cases
- Check CSP after changing CDN, analytics, or frontend bundles.
- Find overly broad source expressions before hardening.
- Compare enforced and Report-Only rollout signals.
How it works inside
Meta CSP has limitations and does not replace the HTTP header for frame-ancestors.
Policy tightening should use a report-only rollout and validation of actual resources.
Questions and answers
Does this duplicate Security Headers Checker?
No. Security Headers Checker covers the general header set; this tool parses CSP structure and source expressions.
Does pass guarantee XSS protection?
No. Pass only means the selected risky constructions were not found in the bounded static review.
