SSL & Web Headers100% In-BrowserPolicy Linter

CSP Policy Validator

Audit existing Content Security Policy strings for unsafe-inline, wildcard (*), and bypass vulnerabilities.

Real-time processing·No server uploads·Zero telemetry
csp-policy-validator
LIVE
CSP Header Value
B65
CSP Quality Score
Contains 'unsafe-inline' which permits inline script/style execution, neutralizing XSS protection.

How to Use CSP Policy Validator

01

Paste your Content-Security-Policy header value.

02

The validator checks for high-severity weaknesses.

03

Read actionable suggestions to harden policy directives.

Privacy Guarantee

CSP Policy Validator runs 100% client-side in your web browser. Your data, passwords, keys, and files are processed using the Web Crypto API and never transmitted to any server. Zero telemetry, zero storage, zero cloud processing.

Frequently Asked Questions

Why is 'unsafe-inline' dangerous in script-src?

'unsafe-inline' allows execution of inline <script> tags, neutralizing one of the primary defenses against XSS.

Discover More

Related Security Tools

View All Security Tools