Item logo image for Advanced CSP Evaluator

Advanced CSP Evaluator

toolcheckers.com
ExtensionTools4 users
Item media 1 (screenshot) for Advanced CSP Evaluator

Overview

Analyze Content Security Policy headers for any domain. Get security grades, directive analysis, and vulnerability detection.

Advanced CSP Evaluator is a powerful security auditing tool that fetches and analyzes the Content-Security-Policy (CSP) headers of any public domain — giving you a clear security grade, a full directive breakdown, and a prioritized list of vulnerabilities in seconds. Whether you're a security engineer hardening a production app, a developer shipping a new release, or a researcher auditing third-party sites, this extension turns raw CSP headers into actionable insight. ━━━ KEY FEATURES ━━━ 🛡️ Security Grading Receive an A–F grade and a 0–100 score based on CSP best practices, weighted by directive strength and risk exposure. 🔍 Directive Breakdown See every CSP directive in use — default-src, script-src, style-src, frame-ancestors, and more — with plain-English explanations of what each one does and how it's configured. 🚨 Vulnerability Detection Automatically flags common CSP weaknesses, including: • 'unsafe-inline' and 'unsafe-eval' usage • Wildcard sources (*) and overly permissive origins • Missing critical directives (object-src, base-uri, frame-ancestors) • Report-Only mode that isn't actually enforced • Insecure schemes (http:, data:, blob:) where they shouldn't appear 📊 Additional Security Headers Beyond CSP, the extension surfaces the status of related headers like Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy. 📝 Raw Header View Inspect the full, unmodified CSP header exactly as the server returned it — perfect for debugging or sharing with your team. ⚡ One-Click Analysis Just enter a domain (or analyze the active tab) and get a complete report instantly. No accounts, no tracking, no data leaves your browser beyond the HTTP request to the target site. ━━━ WHO IT'S FOR ━━━ • Web developers verifying their CSP deployment • Security engineers performing application audits • Penetration testers and bug bounty hunters • DevOps teams reviewing release readiness • Educators teaching web security concepts

Details

  • Version
    1.0.0
  • Updated
    April 30, 2026
  • Size
    27.01KiB
  • Languages
    English (United States)
  • Developer
    Website
    Email
    Roomikat@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization

Advanced CSP Evaluator has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.

Advanced CSP Evaluator handles the following:

User activity

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

For help with questions, suggestions, or problems, visit the developer's support site

Google apps