Audit tool

Score your Content Security Policy in seconds.

Paste a Content-Security-Policy header value. The evaluator parses every directive, flags risky keywords, surfaces missing critical directives, and returns a 0–100 score with plain-English recommendations.

Input

The header name is optional. Both Content-Security-Policy: ... and the bare value are accepted.

Related reading

Background on the heuristics used by the score.

Next step

Use the score to decide what to change, then jump back into the generator or diff before you enforce anything.

Official references

Standards and guidance behind the score categories.