Skip to content
Browse tools

CSP Checker

Check Content Security Policy headers and understand allowed sources, directives and security restrictions.

Policy ValidationAnalyze CSP directives
Security ReviewIdentify risks & gaps
Developer FriendlyClear actionable results

Fetched by our server, not your browser — a site's CSP header cannot be read cross-origin. Private, loopback and cloud-metadata addresses are refused, and only the headers are read; the page body is never downloaded.

Pasting runs entirely in your browser — nothing is sent anywhere.

Paste a CSP header or check a website URL to start the analysis.
0
Policy Score
Not analyzed
Run the checker to evaluate the policy.
script-src
—
Script execution control
frame-ancestors
—
Clickjacking protection
object-src
—
Plugin content control
0Directives
0Strong controls
0Warnings
0High-risk issues
0Unsafe keywords

โš  Security Notes

Directive Analysis

Recommended Improvements

Normalized Policy

Source Information

Analysis source Manual Policy
Pasted CSP header
Header type Enforced
Content-Security-Policy
HOW IT WORKS

Manual Analysis, or a Real Header Fetch

Pasting a policy runs the entire analysis in your browser - directive parsing, scoring, findings and recommendations - with nothing sent to our server. Checking a live website URL is different: browsers can't read another origin's response headers cross-origin because of CORS, so that mode calls our own backend, which validates the URL, blocks private/loopback/link-local/cloud-metadata addresses, follows a limited number of redirects, and reads only the Content-Security-Policy and Content-Security-Policy-Report-Only response headers - the response body is never downloaded.

What else can you check?

These tools all work on the same connection and address data — pick whichever question you actually have.

Want to see the full path to a site? DNS, redirects, every hop, the CDN, TLS and the origin server. Want to know your public IP? See your IPv4 and IPv6 addresses, location, ISP and ASN. Want to check your tower & route? Live ping, speed, DNS, traceroute and a map of nearby points. Want to ping from around the world? Real latency from real probes across 12 countries, live on a map. Want to locate any IP address? City, region, country and coordinates for any public IP. Want to know if an IP is risky? Proxy, VPN, Tor, hosting and abuse-report indicators. Want to know if you're blacklisted? Check an address against major spam and abuse DNSBLs. Want to know who owns an IP? Network owner, ASN, CIDR range and abuse contact. Want to explore an AS number? Announced prefixes, BGP neighbours and registry details. Want to test your connection speed? Measure real download, upload, ping and jitter. Want to see what changed? Word-level diff between two blocks of text or code. Want to know if a DNS change is live yet? Compare answers from five independent public resolvers. Want to verify a domain's nameservers? Direct authoritative checks, glue records and SOA serials. Want to check a domain's DNSSEC setup? DNSKEY, DS records, signature expiry and real validation. Want to see the hop-by-hop path to a server? A real traceroute from a genuine probe anywhere in the world. Want to know if a server port is open? A real TCP connection attempt - open, closed or filtered. Want to measure latency to a server? Real connect timing - min/avg/max, jitter and connection loss. Want a clean URL slug from a title? Real transliteration, stop words and batch mode. Want to find and replace across a document? Regex, capture groups and a live preview before you commit. Want to find the invisible character? Code points, escapes, bytes and hidden-character detection. Want to escape text for HTML? Minimal, named or numeric entities, attribute-safe. Want to strip emoji cleanly? Whole clusters - no half-flags or stray modifiers left. Want to spot repeated words? Frequency, density and accidental doubles like "the the". Want to know if a URL is cached? Two requests prove whether your CDN is really caching it. Want to see what a site knows about you? Storage, cookies, tokens and what your browser actually cached. Want to run that check on any site? One-click bookmarklet reads storage and tokens where they live. Want to know who your site talks to? Renders the page and names every outside company it contacts. Is your site one address or four? www, non-www, http and https - which serve, which redirect. Need to build an Authorization header? Basic, Bearer, API key, Digest and AWS SigV4 - signed in your browser. Want to tidy up a messy SQL query? Beautify, minify, lint and convert keyword casing for six dialects. Need to work out a percentage? Nine calculators covering every way a percentage gets asked. Want to work out a rise or a raise? Increases, growth, compounding and CAGR, with the working shown. Want to work out a discount or a drop? Discounts, stacked sales and depreciation, with the working shown. What is actually on that page? Words, reading time, readability, every image, embed and link. Need a favicon that works everywhere? Every size, a real multi-resolution .ico, and the tags to paste. What headers does a site send back? Every response header on every redirect hop, explained. Need to test a regular expression? Live matches, capture groups, replace preview and code snippets. Need a JPG as a PNG? Batch convert in your browser, with optional transparent background. Need somewhere to jot things down? Private notes, links, to-dos and reminders saved in your browser. Need just some pages of a PDF? Split by page, range or chunk, or extract the pages you pick. What is hiding inside that image? EXIF camera settings, GPS tags, colour palette and web checks.
COMMON QUESTIONS

CSP Checker FAQ

Does pasting a policy send it to your server?

No. Manual policy analysis - parsing, scoring, findings, recommendations - runs entirely in your browser's JavaScript. Nothing is uploaded.

Why does "Check Website URL" need a backend?

Browser JavaScript can't read another origin's response headers due to the same-origin policy and CORS, so fetching a target site's real CSP headers has to happen server-side.

Can I check an internal or private URL?

No. Hostnames that resolve to localhost, private IP ranges, link-local addresses or cloud metadata endpoints are rejected before any request is made, and each redirect hop is re-validated the same way.

What if a site only sends Content-Security-Policy-Report-Only?

It's still fetched and shown, labeled "Report Only" - that header reports violations without blocking anything, so it's a weaker signal than an enforced policy.

How is the score calculated?

It starts at 100 and deducts points for missing or weak directives (no default-src, no script-src restriction, unsafe-inline/unsafe-eval, wildcard sources, missing frame-ancestors, and more) - the same checks listed under Security Findings.

CSP Checker scoring a Content-Security-Policy directive by directive and flagging the unsafe ones
CSP Checker: Score a Content-Security-Policy and flag the risky directives.