CSP Evaluator

A Google web tool that checks whether a Content Security Policy mitigates cross-site scripting.

These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.

About CSP Evaluator

CSP Evaluator reviews a Content Security Policy and reports weak directives and subtle bypasses that would let cross-site scripting through. Its checks are based on a large-scale study of real policies.

You can evaluate a policy against CSP version 1, 2 or 3, including nonce-based policies with backward compatibility checks. Sample safe and unsafe policies are provided. The tool is also available as a Chrome extension. Google provides it without guarantees.

Strengths

  • Finds CSP bypasses that are easy to miss by hand
  • Evaluates against CSP versions 1 to 3
  • Sample policies to learn from
  • Also available as a Chrome extension

Limitations

  • Covers CSP only, not other headers
  • Provided without guarantees or warranties

Details

Pricing
FreeFree to use.
License
Proprietary
Developer
Google
Platforms
Web, Browser extension
How it runs
Web application, Browser extension
Works offline
No
Best suited for
Developers hardening a Content Security Policy against XSS
Categories
Website testing
Last verified
Added
Provenance
Selected from the TechWalrus Resource Hub (Website Checkers & Audit Tools); facts checked against the developer's own pages, 2 sources on file.

Report a wrong fact or a dead link on this listing