Security Tools

🧯 CSP Evaluator

Paste a real Content-Security-Policy (from a header or a <meta>) and get an A–F grade with its bypasses: effective unsafe-inline, data: or wildcards in script-src, and missing object-src, base-uri or frame-ancestors. Nothing is sent. Want to build one from scratch? Use the CSP Builder.