Generates a Content Security Policy directive by directive (sources, schemes, nonces, hashes, 'strict-dynamic'), with output as an enforcement header, a Report-Only header, a <meta> tag, or a sample Next.js configuration. Analyzes a pasted policy, detecting duplicate directives, unknown values, broad wildcards, 'unsafe-inline'/'unsafe-eval', missing object-src/base-uri/frame-ancestors/form-action, and quoting errors. It never tests the policy against a real URL and never claims CSP replaces escaping and sanitizing content.
Data is processed on your device and never sent to the server.
CSP is an additional layer and doesn't replace escaping, validation, and sanitization of content.
Report-Only lets you observe issues before enforcing the policy, but doesn't block any resources.
The data is processed on your device and is never sent to the server.