Security and networkingChecked through WebDiag API

Content Security Policy Analyzer

Enter a URL for a bounded policy review without executing the page, producing a fake security score, or claiming protection from every XSS scenario.

  • header + meta
  • Report-Only
  • directives and sources
Online tool

Try the tool

Enter a URL: WebDiag will run a safe network check and show the result.

Page URL

Network check through backend

For HTTP/SEO tools, the URL is sent to the WebDiag API, where SSRF protection, DNS/IP policy, and redirect limits are applied.

Reviewed: 2026-07-17
01

How to use it

  1. 1

    Enter a public http/https URL.

  2. 2

    Run CSP response-header and static-meta parsing.

  3. 3

    Review risky sources, missing directives, and meta-policy limits.

02

What the tool can do

  • Parses enforced CSP, Report-Only, and meta CSP.
  • Shows directives, values, and duplicate directives.
  • Flags unsafe-inline, unsafe-eval, wildcard, and missing key directives.
03

Common use cases

  • Check CSP after changing CDN, analytics, or frontend bundles.
  • Find overly broad source expressions before hardening.
  • Compare enforced and Report-Only rollout signals.
04

How it works inside

Meta CSP has limitations and does not replace the HTTP header for frame-ancestors.

Policy tightening should use a report-only rollout and validation of actual resources.

05

Questions and answers

Does this duplicate Security Headers Checker?

No. Security Headers Checker covers the general header set; this tool parses CSP structure and source expressions.

Does pass guarantee XSS protection?

No. Pass only means the selected risky constructions were not found in the bounded static review.