Security & CSP Checker reads the response headers of the page you are on and grades them — Content Security Policy, HSTS, Referrer-Policy, the Cross-Origin family and more — then breaks the CSP down directive by directive and names the sources that weaken it.
Security headers are easy to get wrong and hard to check. The values live on the server, the policies are long single-line strings, and the mistakes are quiet: a Content Security Policy that still allows 'unsafe-inline' looks like a policy but stops almost nothing. The usual answer is to paste your URL into an online scanner, which only works for pages a scanner can reach — not a staging site, not an internal tool, not a page behind a login.
This tool checks the page in front of you, signed in as you are. It reads the document's response headers and gives each one a pass, a warning or a failure with a plain explanation: whether a CSP exists at all, whether HSTS will keep browsers on HTTPS, whether MIME sniffing is off, whether referrers leak full URLs, and what the Cross-Origin-* headers are set to. It also points out headers that give away more than they should, such as Server and X-Powered-By naming your exact framework version.
The CSP tab is the heart of it. The policy is split into directives, every source is colour-coded, and the findings read like a review: 'unsafe-inline' in script-src is marked as a failure, 'unsafe-eval' and wildcard origins as warnings, and data: in script-src as the bypass it is. It knows the rules that trip people up — that 'unsafe-inline' is ignored once a nonce or hash is present, so that case is a warning rather than a failure, and that 'strict-dynamic' replaces host allowlists. Missing directives are called out too: no object-src, no base-uri, no frame-ancestors, no form-action. Policies delivered by meta tag and report-only policies are shown separately, because they behave differently.
The Connection tab covers what HTTPS is actually doing: the TLS handshake, HSTS max-age against the one-year threshold that preloading requires, includeSubDomains and preload flags, and every insecure subresource or form target that undermines an HTTPS page. One thing it does not claim: certificate details. No browser extension can read the certificate chain, issuer or expiry date, so rather than invent them the tool says where to look — the padlock in your address bar, or an external service for the full chain.
CSP, HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy and the Cross-Origin family, each with a pass, warning or failure and a plain explanation of what its absence means.
The policy is parsed into directives with every source colour-coded, so a dangerous value stands out instead of hiding inside a 500-character header string.
Flags 'unsafe-inline', 'unsafe-eval', wildcards and data: in script-src — but treats 'unsafe-inline' as a warning when a nonce or hash makes browsers ignore it, and credits 'strict-dynamic' and report-uri.
A policy without object-src, base-uri, frame-ancestors or form-action is reported with the specific risk each gap leaves open, including when default-src already covers one of them.
HSTS max-age against the one-year preload threshold, the TLS handshake time, and every http:// subresource or form target that undermines an HTTPS page, listed with its selector.
Headers are read from the page you are already viewing, with your session, so internal tools and pre-production sites can be checked — no public URL for a scanner to reach.
Walk the checklist on the real page: confirm the CSP is enforced rather than report-only, HSTS is set for a year, and nothing is still loading over http://.
Online header checkers need a public URL. This reads the page you are viewing, so a staging environment behind basic auth or a VPN is just as easy to check.
See at a glance whether a long policy actually restricts anything, or whether 'unsafe-inline' and a wildcard host have quietly turned it into decoration.
Find the exact image, script or form action still using http:// on an HTTPS page, with the element's selector, instead of hunting through the console.
Copy a dated report of every header, its value and its verdict to attach to an audit, a pentest follow-up or a compliance questionnaire.
Click the Security & CSP icon in the DevSuite Pro dock. The check runs immediately and the summary shows how many headers passed, warned or are missing.
The Headers tab lists each security header with its value and a verdict. Below it are the information-disclosure check and the document's CORS headers.
Open the CSP tab for the findings list, then the parsed directives. Red sources are failures, amber ones are worth a second look, green ones are what a strong policy uses.
The Connection tab covers HTTPS, the TLS handshake, HSTS and any mixed content. For the certificate itself, click the padlock in the address bar — no extension can read it.
Copy report produces a plain-text summary of every verdict, the CSP findings and any mixed content, ready for a ticket or a security review.
Install DevSuite Pro for free and unlock 71+ developer tools for your browser.