CSP Validator
Paste one CSP policy or response header to find common syntax mistakes and permissive settings. Results stay in this browser and are guidance for review, not a full browser-conformance or security audit.
Paste one policy or a Content-Security-Policy header. Maximum 65,536 characters. This checks common structure and risky settings, not full browser conformance.
Paste one policy or a Content-Security-Policy header. Maximum 65,536 characters. This checks common structure and risky settings, not full browser conformance.
Findings
A missing fallback or risky source may be intentional for your site. Review each finding and test changes in Report-Only before enforcement.
A QUICK WALKTHROUGH
How to use this tool
- Paste one policy or a Content-Security-Policy response header up to 65,536 characters.
- Select Check policy to review directive names, duplicates, required values, fallback directives, and common risky sources.
- Review the findings, then test any change with Report-Only on your own site.
Common structure checks
Recognized directive names, repeated directives, missing values, values on valueless directives, malformed names, and unknown directives are reported. It accepts a single policy, optionally preceded by a Content-Security-Policy or Content-Security-Policy-Report-Only header name.
Common hardening reminders
The checker flags wildcard sources, 'unsafe-inline', 'unsafe-eval', a mixed 'none' source list, deprecated report-uri, and missing default-src, object-src, or base-uri directives. These are review prompts, not automatic proof that a policy is vulnerable; a site may have specific compatibility requirements.
A focused local check, not an audit
The tool uses a known directive list and checks common structural patterns. It is not a complete CSP grammar implementation, does not inspect your site or network traffic, cannot know which origins your application needs, and does not install or enforce a policy. Test changes in Report-Only and review browser reports before enforcement.
GOOD TO KNOW
Common questions
Does a clean result prove my policy is secure?
No. The checker only reports the listed common issues. It does not inspect application behavior, all CSP rules, browser support, or the resources your site needs.
Why does it warn when default-src is missing?
default-src acts as a fallback for several fetch directives. Without it, directives that are also absent may allow resources the policy author did not intend.
Is unsafe-inline always a mistake?
Not in every compatibility situation, but it can weaken protections against injected inline scripts or styles. Review whether a nonce or hash can meet the need instead.
Is my policy uploaded?
No. The text is checked locally in your browser.