Cybersecurity · free, no signup
CSP & Web Security Policy Analyzer
Paste your Content-Security-Policy — and optionally the other policy headers alongside it — to see what the browser will really permit. Every directive is evaluated against its own source expressions, so a policy that looks strict but allows script injection through a wildcard, an unsafe keyword or a permissive scheme is reported as what it is, with the exact fragment quoted as evidence.
Authorized, defensive use only. Check assets you own or lawfully public data. This tool is educational and never provides another party's private data.
Paste the Content-Security-Policy header value. The other fields are optional — supplying them lets the analysis reason about the policy in the context of the rest of your header posture. Nothing is fetched and nothing is stored: the policy is hashed for rate accounting and discarded.
What happens to what you enter
- The analysis runs on Solvex servers. What is recorded afterwards is a SHA-256 hash of your input and a coarse summary of the outcome — never the input itself, and never a result you could be identified from.
- Tools that read public sources (certificate logs, DNS, a public chain) contact those sources from our servers through a fetcher that refuses private and internal addresses.
- An email address is stored only where a tool offers to send you a report and you choose to give one.
Limits: ten runs of this tool per minute from one address, and three signed reports per minute. Past that the tool says so and tells you when to try again.
When a free check is not enough
This tool reads what is public and reports what it can see. The Web Application Penetration Testing engagement is the authorized, specialist-led version: signed scope, findings proven by hand, a signed report, and a retest.
Explore Web Application Penetration Testing