WoluTools

CSP evaluator

Check a Content Security Policy for weak rules

Paste the Content-Security-Policy header from your browser developer tools, curl or server config. Findings appear on this page as you paste: warnings for a missing default-src or sources that allow too much, such as 'unsafe-inline' or wildcards, and review points for hosts to confirm.

The check runs in this browser tab and has no daily limit. Nothing you paste leaves the page unless you choose to get the download files.

Findings show up here as soon as you paste a policy. No policy at hand? Choose Try with sample.

  • Counts of directives, errors, warnings and review points
  • Each finding with the part of the policy it refers to
  • A tidied draft as a Report-Only or Enforce header

Policy already saved as a file? Add it here and the workspace opens with it.

or drop the .txt file here

The full header line or only the policy text · up to 10,000 directives · opens the workspace

Free account needed for the download files · 3 jobs a dayPro: up to 200 a day

BringThe header line, pasted or as .txt
GetFindings on the page · policy.txt, findings.csv, manifest.json
PrivacyPaste check stays in your browser · results expire after 24 hours

What the check flags

The check on this page and the download files use the same rules.

What the download contains

From header to download

  1. 1

    Paste the policy

    The header line or only the policy text. Findings and a tidied draft appear on the page.

  2. 2

    Open the workspace

    Your paste goes over as policy.txt, or add a .txt file. Pick Report-Only or Enforce and confirm you may process it.

  3. 3

    Download the files

    With a free account, get policy.txt, findings.csv and manifest.json. Results expire after 24 hours.

Review a Content Security Policy for loose rules

What the check reads

It reads the policy text you paste or upload, with or without the Content-Security-Policy: prefix. The check is textual. No website is fetched, no script runs and no browser behaviour is simulated. That also means it cannot tell you whether your policy covers every resource your site loads.

Why hosts become review points

A host you allow, including your own origin or a CDN, can still serve scripts you did not write, such as JSONP endpoints or user uploads. The check cannot see what a host serves, so it lists those sources for someone who knows the host to confirm.

Report-Only or Enforce, and your decision

Report-Only lets you run the draft next to your current policy and collect violation reports before anything is blocked. The tool never applies either version to a server. A clean result does not mean your site is safe from cross-site scripting. Whether and when to enforce the policy remains your call.

Questions before you run it

Which CSP directives and source tokens does the workbench recognise?

It inventories the directive names and source expressions present in the supplied policy text, including keywords such as self, none and unsafe-inline alongside host and scheme sources. A token it cannot classify is listed as a review point rather than passed over.

Can I paste a CSP response header instead of a policy file?

Yes. Paste the full header line or only the policy text into the box at the top of this page and the findings appear below it. For the download files, the workspace takes the pasted text as policy.txt, or you add your own .txt file, up to 10,000 directives.

Why is the exported draft marked Report-Only?

Report-Only lets you deploy the draft next to your current policy and collect violation reports before anything is enforced. Draft mode also offers Enforce, but neither setting is applied to a server by this tool.

Does a clean report mean my policy blocks XSS?

No. The pass is offline and textual: no site is fetched, no script runs and no browser behaviour is simulated. Completeness against real browsers is not claimed.

What do the review points on host sources mean?

An origin the policy allows, including self and a CDN host, can still serve JSONP endpoints, script gadgets or user-uploaded JavaScript. Those sources are flagged so someone who knows what the origin hosts can confirm them.