Running on your device · 0 bytes uploaded Content Security Policy evaluator and builder Paste a policy for csp_evaluator's findings, or build one directive by directive — then read what it still allows. Google's evaluator, running in your tab. Evaluate a policyBuild a policyContent Security Policy - Highscript-src'unsafe-inline''unsafe-inline' allows the execution of unsafe in-page scripts and event handlers. - Highscript-srchttps:https: URI in script-src allows the execution of unsafe scripts. - Possibly mediumscript-src'self''self' can be problematic if you host JSONP, AngularJS or user uploaded files. Findings come from csp_evaluator with CSP3 semantics — a static read of the policy text, not a crawl of your site. “No findings” is not “no bypasses”: it means the evaluator found nothing in the text alone. default-src'self'script-src'self' 'unsafe-inline' https:object-src'none' - It never fetches your site — the evaluator reads policy text only. Bypasses that need your markup are out of scope. - The builder offers the spec's keywords, not a wizard that knows your app: a safe CSP is written against what your pages actually load. - frame-ancestors and report-to are header-only — a CSP ignores them (the evaluator will not warn for you). Done Finished here in the tab. Nothing was uploaded. csp_evaluator (Google) — CSP3 semantics, static analysis only Next door in Web - Subresource integrity (/web/sri) - Deep probes (/browser/probes) All web tools (/web) Canonical HTML: https://nutter.tools/web/csp Markdown version: https://nutter.tools/web/csp/index.md Plain-text version: https://nutter.tools/web/csp/index.txt Agent index: https://nutter.tools/llms.txt