CSP Evaluator
- Live on Store
CSP Evaluator is a tool that allows developers to check if a Content Security Policy (CSP) serves as mitigation against XSS attacks.
CSP Evaluator is a small tool that allows developers and security experts to check if a Content Security Policy (CSP) serves as a strong mitigation against cross-site scripting attacks. Reviewing CSP policies is usually a very manual process and most developers are not aware of CSP bypasses.
CSP Evaluator checks are based on a large-scale empirical study and are aimed to help developers to harden their CSP. This tool is provided only for the convenience of developers and Google provides no guarantees or warranties for this tool.
Latest reviews
In every page i tried it it said: "No Content Security Policy found". And yes, these pages had CSP configured.
Works great!
It works just fine.
extension stopped working :(
This extension stopped working for me in the past couple months in the Brave browser. I recently disabled, removed, and reinstalled and it's working again. For those who are having trouble with it working, give the reinstall a try.
Was great until it stopped working for me. Please fix and I'll change my rating
I this thing stopped working :/
I have a CSP but this doesn't detect it. So disappointed.
It doesn't detect meta CSP and it doesn't say anything about it on the description
It doesn't detect meta CSP and it doesn't say anything about it on the description
For some unknown reason, when the extension was enabled, my browser sent additional requests to the sites. As a result, I lost a lot of hours debugging my site and trying to find the cause of the duplicate requests. As soon as I turned off the extension, the problem disappeared.
For some unknown reason, when the extension was enabled, my browser sent additional requests to the sites. As a result, I lost a lot of hours debugging my site and trying to find the cause of the duplicate requests. As soon as I turned off the extension, the problem disappeared.
Macht wenig überraschend exakt das was dran steht. Keine Ahnung was an anderer Stelle schief gegangen ist, aber es funktioniert sogar in Edge.
Keeps crashing in Chrome 104
Keeps crashing in Chrome 104
used it sometime ago and it was working just fine, with current version of chrome is not working anymore, it keeps crashing Version 104.0.5112.101
used it sometime ago and it was working just fine, with current version of chrome is not working anymore, it keeps crashing Version 104.0.5112.101
No CSP detected on any webpage.
No CSP detected on any webpage.
liked it. saved me some headaches!!! was playing around for weeks to get my csp right! there's one drawback though. after copying it all to my policy file it bricked my wordpress login page. so i had to revert back using ftp access to my server to find the problem..... again.
liked it. saved me some headaches!!! was playing around for weeks to get my csp right! there's one drawback though. after copying it all to my policy file it bricked my wordpress login page. so i had to revert back using ftp access to my server to find the problem..... again.
No CSP detected on any webpage.
No CSP detected on any webpage.
It doesn't detect meta CSPs which should have been stated in the extension details.
It doesn't detect meta CSPs which should have been stated in the extension details.
cool. May be better if it's possible to add/remove CSP directives so I can test without deploying codes lol
cool. May be better if it's possible to add/remove CSP directives so I can test without deploying codes lol
doesn't detect CSP in page meta tags
doesn't detect CSP in page meta tags
Doesn't detect CSP on any websites I tested!
Спасибо!
Where to post the issues? It shows 'Directive "prefetch-src" is not a known CSP directive.', https://w3c.github.io/webappsec-csp/#directive-prefetch-src
Where to post the issues? It shows 'Directive "prefetch-src" is not a known CSP directive.', https://w3c.github.io/webappsec-csp/#directive-prefetch-src
It appears that the extension does not consider CSP in meta tags.
It appears that the extension does not consider CSP in meta tags.
Супер!