Tools
Web Security

CSP Analyzer

Break down a Content-Security-Policy and flag weak directives.

Input

Output

Results appear here.

How this helps

CSP is the single strongest mitigation against injected scripts — weak directives quietly disable it.

Everything runs locally in your browser. Never paste production secrets, tokens or real credentials into any online tool.