CSP

Would it stop an injected script — or just look like it would?

Nine checks on the live Content-Security-Policy — script-src lockdown, unsafe-inline and eval, object-src, base-uri, form-action, frame-ancestors, report-only traps — read the way an attacker reads it, not the way a linter does.

Try: this site · example.com  |  Header scanner → · Email check → · Accessibility →

Try it live — real grades

github.com check → stripe.com check → cloudflare.com check → example.com check →