CSP Evaluator & Bypass Finder

Analyze Content Security Policy headers for vulnerabilities. Identify misconfigurations, JSONP bypasses, and get actionable bypass payloads.

346
Bypass Payloads
330
Unique Domains
50+
AngularJS Bypasses

Enter CSP Header

Quick Examples

Find CSP Bypasses

Paste a Content-Security-Policy header and click "Analyze CSP" to find bypass payloads that work for your target.

346 bypass payloads
JSONP callback gadgets
AngularJS template injection
CDN script gadgets

Quick CSP Reference

script-src

Controls sources for JavaScript. Most critical directive for XSS prevention.

default-src

Fallback for other directives. Use 'none' or 'self' as baseline.

base-uri

Restricts URLs for <base> element. Missing = base tag injection possible.

object-src

Controls plugins (Flash, Java). Should be 'none' in modern apps.

frame-ancestors

Prevents clickjacking. Replaces X-Frame-Options header.

form-action

Restricts form submission targets. Prevents form hijacking attacks.

Copied to clipboard!