FlowingDev

CSP Checker Free

Scan your CSP header for sketchy directives and gaps. Your data never leaves this browser.

CONTENT-SECURITY-POLICY1 lines
default-src'self'
script-src'self' https://cdn.example.com 'unsafe-inline'
img-src*
style-src'self'
upgrade-insecure-requests(flag)

risk'unsafe-inline' in script-src

Inline code is allowed, which enables XSS. Prefer nonces or hashes.

warningWildcard source in img-src

* allows any origin. Restrict to specific trusted hosts.

warningMissing object-src

Set object-src 'none' to block plugins like Flash.

warningMissing base-uri

Set base-uri 'none' to prevent base-tag hijacking.

warningMissing frame-ancestors

Set frame-ancestors 'none' or 'self' to prevent clickjacking.

goodupgrade-insecure-requests enabled

HTTP subresources are upgraded to HTTPS.

Ready