CSP
Would it stop an injected script — or just look like it would?
Nine checks on the live Content-Security-Policy — script-src lockdown, unsafe-inline and eval, object-src, base-uri, form-action, frame-ancestors, report-only traps — read the way an attacker reads it, not the way a linter does.
- 9 checks
- Reads the live policy
- Report-only traps caught
- Free, no account
Try: this site · example.com | Header scanner → · Email check → · Accessibility →