ToolCabana
Language preview: no interface translation is available for this language yet. Showing English. Use English

Content Security Policy analyzer

Explain pasted directives and identify common configuration issues.

Favorites are saved in this browser. Find them in My favorites.

Content Security Policy analyzer

Your input stays in this browser unless stated otherwise
Clear your input, files and result, and restore the default settings.
Load sample text to explore what this tool can do. This replaces your current input.
0 charactersClear the source text.

How to use Content Security Policy analyzer

Content Security Policy analyzer splits a pasted CSP into directives and lists each with its values and a review note. It flags 'unsafe-inline', 'unsafe-eval', bare wildcard sources, 'none' combined with other sources, and duplicate directives, and adds rows when object-src, base-uri or frame-ancestors is missing. Results are static heuristics for learning and review.

  1. Paste the source into the input editor, or load the built-in example.
  2. Check the source format before running the operation.
  3. Run content security policy analyzer, review the output, then use the available copy or download controls.

What this tool supports

Explain pasted directives and identify common configuration issues.

Limits and processing

CSV/XLSX inputs are capped at 10 MB each, 200 columns and 20,000 rows; joined output is capped at 20,000 rows. JSONPath script/filter evaluation is disabled. Other operations apply their visible controls and text limits.

Example source
default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'

Frequently asked questions

What happens if a CSP has the same directive twice?

The analyzer marks the repeat as a duplicate and notes that browsers use the first occurrence, so values in the later copy are ignored. Merge the sources into a single directive to make the policy behave as intended.

Why does the CSP analyzer warn that object-src is missing?

object-src, base-uri and frame-ancestors are checked separately as common hardening directives. If one is absent, a row marked missing suggests reviewing whether an explicit restriction is needed; the check does not account for any default-src fallback.

Should I paste the full header line including Content-Security-Policy:?

Paste only the policy value. Directives are split on semicolons and the first word of each is read as the directive name, so a header prefix would be treated as the first directive's name. Up to 100 directives are accepted.

Where is my input processed?

This operation processes its source in your browser. Copy and download are explicit actions; source input is not saved in an account or history.

What are the input limits?

CSV/XLSX inputs are capped at 10 MB each, 200 columns and 20,000 rows; joined output is capped at 20,000 rows. JSONPath script/filter evaluation is disabled. Other operations apply their visible controls and text limits.