Skip to main content
QUIETLYTIC
Cybersecurity

CSP Analyzer

Break a Content-Security-Policy into its directives and flag the weak ones.

Local · nothing leaves this browser Waiting for input
Esc Clear
Directives

Paste a Content-Security-Policy on the left.

How it works

A CSP is a list of directives, each naming where one kind of content may come from. Reading one is mostly mechanical. Two of its rules are not, and between them they account for most policies that look strict and are not.

A nonce makes 'unsafe-inline' disappear

CSP Level 3 requires browsers to ignore 'unsafe-inline' in a directive that also carries a nonce or a hash. Careful policies leave the keyword in deliberately, as a fallback for browsers that only implement Level 2. So 'unsafe-inline' is flagged as critical on its own and reported as inert next to a nonce — a checker that flags it unconditionally is wrong about exactly the policies written most carefully.

default-src does not cover everything

base-uri, form-action, frame-ancestors and sandbox have no fallback. A policy of default-src 'self' and nothing else leaves all four unrestricted, which means an injected <base> tag can rewrite every relative URL on the page, including the script sources the policy was written to constrain.

What is not checked

This reads the policy string. It does not load a page, so it cannot tell you whether a host in your allowlist serves a JSONP endpoint or an old AngularJS build — either of which turns an allowlisted origin into script execution. A syntactically strict policy can still be bypassable through what it allows.

Example

script-src 'strict-dynamic' 'nonce-abc' https://cdn.example.com does not allow the CDN. Under 'strict-dynamic' host sources are ignored entirely and trust propagates from the nonced script instead — the URL is kept only for Level 2 browsers. A misspelled directive such as script-source is dropped by the browser with no error at all, which is why it is reported here as an alert rather than a note.

Frequently asked questions

Why is unsafe-inline sometimes reported as fine?

Because CSP Level 3 requires browsers to ignore it in a directive that also carries a nonce or hash. Careful policies keep the keyword as a fallback for Level 2 browsers, so flagging it unconditionally would be wrong about exactly those policies.

Does default-src cover every directive?

No. base-uri, form-action, frame-ancestors and sandbox have no fallback. A policy of default-src ’self’ and nothing else leaves all four unrestricted.

What does strict-dynamic change?

It makes browsers ignore host and scheme sources in that directive entirely. Trust propagates from a nonced or hashed script to whatever it loads, so the allowlist beside it is dead text kept for older browsers.

Why is a misspelled directive an alert rather than a note?

Because browsers drop an unknown directive silently. There is no console error and no protection — the policy reads as though it covers something it does not.

Can a strict-looking policy still be bypassed?

Yes, and this page cannot tell you. A host in your allowlist that serves a JSONP endpoint or an old AngularJS build turns an allowlisted origin into script execution. That needs the hosts checked, not the policy string.

Related tools

From the intelligence desk