CSP Evaluator
A Google web tool that checks whether a Content Security Policy mitigates cross-site scripting.
These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.
About CSP Evaluator
CSP Evaluator reviews a Content Security Policy and reports weak directives and subtle bypasses that would let cross-site scripting through. Its checks are based on a large-scale study of real policies.
You can evaluate a policy against CSP version 1, 2 or 3, including nonce-based policies with backward compatibility checks. Sample safe and unsafe policies are provided. The tool is also available as a Chrome extension. Google provides it without guarantees.
Strengths
- Finds CSP bypasses that are easy to miss by hand
- Evaluates against CSP versions 1 to 3
- Sample policies to learn from
- Also available as a Chrome extension
Limitations
- Covers CSP only, not other headers
- Provided without guarantees or warranties
Details
- Pricing
- FreeFree to use.
- License
- Proprietary
- Developer
- Platforms
- Web, Browser extension
- How it runs
- Web application, Browser extension
- Works offline
- No
- Best suited for
- Developers hardening a Content Security Policy against XSS
- Categories
- Website testing
- Last verified
- Added
- Provenance
- Selected from the TechWalrus Resource Hub (Website Checkers & Audit Tools); facts checked against the developer's own pages, 2 sources on file.