Build, test, and refine your CSP headers visually. Get instant security scores, scan live sites for resources, and manage policies without writing raw header strings.
Everything you need to create, validate, and deploy Content Security Policies.
Edit all 12 CSP directives through an intuitive card-based interface. Color-coded badges for keywords, domains, hashes, and unsafe values make policies easy to read at a glance.
Get a 100-point security rating with letter grades. Detailed findings highlight critical issues, warnings, and bonuses with exact point values so you know what to fix first.
Scan any website to automatically discover external scripts, styles, images, fonts, frames, and connections. One click adds discovered domains to the right directives.
Paste a CSP string or fetch headers directly from a live URL. Supports both Content-Security-Policy and Report-Only headers with auto-detection.
View your policy in formatted or raw mode. One-click copy to clipboard gives you a ready-to-deploy header string with character count.
Save dated snapshots of your configurations with optional labels. Restore any previous version or delete old ones. Experiment freely without losing work.
Instant warnings on each directive card flag issues like unsafe-inline, wildcard abuse, missing 'self', and duplicates before you deploy.
An interactive 11-slide guide covers what CSP is, why it matters, common mistakes, and deployment steps. Learn as you build, no external docs needed.
All data is saved to your browser's local storage. No sign-ups, no databases, no tracking. Your policies stay on your machine.
From zero to a production-ready CSP in minutes.
Paste an existing CSP header, fetch one from a live site, or start from a blank slate. The editor parses everything into visual directive cards.
Enter your URL and the scanner discovers every external resource your site loads — scripts, stylesheets, fonts, images, and more. Add them to the right directives with one click.
Add or remove sources from each directive. Real-time validation flags unsafe values and missing best practices. Watch your security score climb as you tighten the policy.
Copy the generated header string and add it to your server config — Nginx, Apache, Express, or an HTML meta tag. Save a snapshot to the archive for safe keeping.
Know exactly how strong your policy is and what to improve.
Manage the 12 most critical CSP directives.
default-srcFallback for all resource types
script-srcJavaScript files
script-src-elemScript elements
style-srcCSS stylesheets
style-src-elemStyle and link elements
img-srcImages
font-srcWeb fonts
connect-srcXHR, Fetch, WebSocket
frame-srcIframes and embeds
base-uriBase element URLs
worker-srcWeb Workers
object-srcPlugins (Flash, Java)
Start building your Content Security Policy in minutes. Free, no sign-up required.
Launch the Editor →