CSP Analyzer
Break a Content-Security-Policy into its directives and flag the weak ones.
Paste a Content-Security-Policy on the left.
How it works
A CSP is a list of directives, each naming where one kind of content may come from. Reading one is mostly mechanical. Two of its rules are not, and between them they account for most policies that look strict and are not.
A nonce makes 'unsafe-inline' disappear
CSP Level 3 requires browsers to ignore 'unsafe-inline' in a directive that also carries a nonce or a
hash. Careful policies leave the keyword in deliberately, as a fallback for browsers that only implement Level 2.
So 'unsafe-inline' is flagged as critical on its own and reported as inert next to a nonce — a
checker that flags it unconditionally is wrong about exactly the policies written most carefully.
default-src does not cover everything
base-uri, form-action, frame-ancestors and sandbox have no
fallback. A policy of default-src 'self' and nothing else leaves all four unrestricted, which means
an injected <base> tag can rewrite every relative URL on the page, including the script sources
the policy was written to constrain.
What is not checked
This reads the policy string. It does not load a page, so it cannot tell you whether a host in your allowlist serves a JSONP endpoint or an old AngularJS build — either of which turns an allowlisted origin into script execution. A syntactically strict policy can still be bypassable through what it allows.
Example
script-src 'strict-dynamic' 'nonce-abc' https://cdn.example.com does not allow the CDN. Under
'strict-dynamic' host sources are ignored entirely and trust propagates from the nonced script
instead — the URL is kept only for Level 2 browsers. A misspelled directive such as script-source is
dropped by the browser with no error at all, which is why it is reported here as an alert rather than a note.
Frequently asked questions
Why is unsafe-inline sometimes reported as fine?
Because CSP Level 3 requires browsers to ignore it in a directive that also carries a nonce or hash. Careful policies keep the keyword as a fallback for Level 2 browsers, so flagging it unconditionally would be wrong about exactly those policies.
Does default-src cover every directive?
No. base-uri, form-action, frame-ancestors and sandbox have no fallback. A policy of default-src ’self’ and nothing else leaves all four unrestricted.
What does strict-dynamic change?
It makes browsers ignore host and scheme sources in that directive entirely. Trust propagates from a nonced or hashed script to whatever it loads, so the allowlist beside it is dead text kept for older browsers.
Why is a misspelled directive an alert rather than a note?
Because browsers drop an unknown directive silently. There is no console error and no protection — the policy reads as though it covers something it does not.
Can a strict-looking policy still be bypassed?
Yes, and this page cannot tell you. A host in your allowlist that serves a JSONP endpoint or an old AngularJS build turns an allowlisted origin into script execution. That needs the hosts checked, not the policy string.
Related tools
Security Headers Analyzer
Review a set of pasted HTTP response headers against current guidance.
LocalCORS Analyzer
Check a set of CORS response headers for the combinations that undo them.
LocalCSP Generator
Build a Content-Security-Policy header directive by directive, not by editing a string.
LocalPermissions-Policy Builder
Turn on, off or origin-scope a browser feature per directive, then copy the header.
LocalSTIX Viewer
Read a STIX 2.1 bundle as structured objects instead of raw JSON.
LocalSTIX Validator
Check a STIX 2.1 bundle for structural and required-property errors.
LocalFrom the intelligence desk
- Vulnerability FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel Vulnerability (CVE-2025-6068)
- Vulnerability HUSKY – Products Filter Professional for WooCommerce Vulnerability (CVE-2026-18562)
- Vulnerability TranslatePress – Translate Multilingual sites with AI Translation Vulnerability (CVE-2026-75981)
- Vulnerability WP Cookie Notice Vulnerability (CVE-2026-82970)