Item logo image for CSP Evaluator

CSP Evaluator

Item media 2 screenshot
Item media 1 screenshot
Item media 2 screenshot
Item media 1 screenshot
Item media 1 screenshot
Item media 2 screenshot

Overview

CSP Evaluator is a tool that allows developers to check if a Content Security Policy (CSP) serves as mitigation against XSS attacks.

CSP Evaluator is a small tool that allows developers and security experts to check if a Content Security Policy (CSP) serves as a strong mitigation against cross-site scripting attacks. Reviewing CSP policies is usually a very manual process and most developers are not aware of CSP bypasses. CSP Evaluator checks are based on a large-scale empirical study and are aimed to help developers to harden their CSP. This tool is provided only for the convenience of developers and Google provides no guarantees or warranties for this tool.

3.0 out of 527 ratings

Google doesn't verify reviews. Learn more about results and reviews.

Review's profile picture

Josh BarberSep 13, 2024

Was great until it stopped working for me. Please fix and I'll change my rating

2 out of 2 found this helpful
Review's profile picture

Paulo LimaSep 12, 2024

I this thing stopped working :/

2 out of 2 found this helpful
Review's profile picture

Barbara RenowdenMar 21, 2024

I have a CSP but this doesn't detect it. So disappointed.

Details

  • Version
    0.3.2
  • Updated
    July 12, 2024
  • Offered by
    Lukas Weichselbaum
  • Size
    297KiB
  • Languages
    English
  • Developer
    Email
    lweichselbaum@google.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

The developer has disclosed that it will not collect or use your data.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

For help with questions, suggestions, or problems, visit the developer's support site

Related

OWASP Penetration Testing Kit

4.8(43)

OWASP Penetration Testing Kit

Disable Content-Security-Policy

3.6(89)

Disable Content-Security-Policy for web application testing. When the icon is colored, CSP headers are disabled.

Xdebug helper

4.4(429)

Easy debugging, profiling and tracing extension for Xdebug

Datalayer Checker

4.7(32)

The easiest way to debug and check the dataLayer implementations without having to use the browser console!

Content Security Policy Override

4.2(9)

Modify the Content Security Policy of web pages.

Content Security Policy (CSP) Generator

4.4(14)

Automatically generate content security policy headers online for any website.

axe DevTools - Web Accessibility Testing

4.0(112)

Accessibility Checker for Developers, Testers, and Designers in Chrome

CSP Tester

3.7(7)

This extension helps web masters to test web application behaviour with Content Security Policy version 2.0 implemented.

Always Disable Content-Security-Policy

3.8(17)

Always Disable Content-Security-Policy for web application testing. When the icon is colored, CSP headers are disabled.

Web Vitals

4.1(43)

Measure metrics for a healthy site

Security-Header-Extension

4.9(7)

A Chrome Extension built to check the presence of embedded security headers.

Caspr: Enforcer

3.7(7)

Install CSP headers on arbitrary websites

OWASP Penetration Testing Kit

4.8(43)

OWASP Penetration Testing Kit

Disable Content-Security-Policy

3.6(89)

Disable Content-Security-Policy for web application testing. When the icon is colored, CSP headers are disabled.

Xdebug helper

4.4(429)

Easy debugging, profiling and tracing extension for Xdebug

Datalayer Checker

4.7(32)

The easiest way to debug and check the dataLayer implementations without having to use the browser console!

Content Security Policy Override

4.2(9)

Modify the Content Security Policy of web pages.

Content Security Policy (CSP) Generator

4.4(14)

Automatically generate content security policy headers online for any website.

axe DevTools - Web Accessibility Testing

4.0(112)

Accessibility Checker for Developers, Testers, and Designers in Chrome

CSP Tester

3.7(7)

This extension helps web masters to test web application behaviour with Content Security Policy version 2.0 implemented.

Google apps