Paste a CSP header or enter a URL to auto-fetch. Get a detailed breakdown of unsafe-inline, wildcards, and missing directives.
Content Security Policy is the browser's primary defense against XSS attacks. A missing or weak CSP is the single most common OWASP A05 finding. Even a present CSP with unsafe-inline is nearly as bad as no CSP at all.
eval() and similar. Enables code injection.