← Back to Features
Pro

Security & CSP Checker

Security & CSP Checker reads the response headers of the page you are on and grades them — Content Security Policy, HSTS, Referrer-Policy, the Cross-Origin family and more — then breaks the CSP down directive by directive and names the sources that weaken it.

Security headers are easy to get wrong and hard to check. The values live on the server, the policies are long single-line strings, and the mistakes are quiet: a Content Security Policy that still allows 'unsafe-inline' looks like a policy but stops almost nothing. The usual answer is to paste your URL into an online scanner, which only works for pages a scanner can reach — not a staging site, not an internal tool, not a page behind a login.

This tool checks the page in front of you, signed in as you are. It reads the document's response headers and gives each one a pass, a warning or a failure with a plain explanation: whether a CSP exists at all, whether HSTS will keep browsers on HTTPS, whether MIME sniffing is off, whether referrers leak full URLs, and what the Cross-Origin-* headers are set to. It also points out headers that give away more than they should, such as Server and X-Powered-By naming your exact framework version.

The CSP tab is the heart of it. The policy is split into directives, every source is colour-coded, and the findings read like a review: 'unsafe-inline' in script-src is marked as a failure, 'unsafe-eval' and wildcard origins as warnings, and data: in script-src as the bypass it is. It knows the rules that trip people up — that 'unsafe-inline' is ignored once a nonce or hash is present, so that case is a warning rather than a failure, and that 'strict-dynamic' replaces host allowlists. Missing directives are called out too: no object-src, no base-uri, no frame-ancestors, no form-action. Policies delivered by meta tag and report-only policies are shown separately, because they behave differently.

The Connection tab covers what HTTPS is actually doing: the TLS handshake, HSTS max-age against the one-year threshold that preloading requires, includeSubDomains and preload flags, and every insecure subresource or form target that undermines an HTTPS page. One thing it does not claim: certificate details. No browser extension can read the certificate chain, issuer or expiry date, so rather than invent them the tool says where to look — the padlock in your address bar, or an external service for the full chain.

Live Preview
example.com
Security & CSP 1 problem, 3 warnings
Headers CSP Connection
5
Passed
3
Warnings
1
Missing
24
Headers
✓
Content-Security-Policy
Present — scripts and other resources are restricted
!
Strict-Transport-Security
max-age is under the 1 year that preload requires
max-age=86400
✗
Referrer-Policy
Missing — full URLs may leak to other sites
Policy findings
✗script-src allows 'unsafe-inline'
!img-src allows *
!No base-uri — an injected tag can rewrite relative URLs
script-src 'self' 'nonce-r4nd0m' 'unsafe-inline' https://cdn.example.com
Key Features

Every Security Header, Graded

CSP, HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy and the Cross-Origin family, each with a pass, warning or failure and a plain explanation of what its absence means.

CSP Broken Down Directive by Directive

The policy is parsed into directives with every source colour-coded, so a dangerous value stands out instead of hiding inside a 500-character header string.

Knows the Rules That Catch People Out

Flags 'unsafe-inline', 'unsafe-eval', wildcards and data: in script-src — but treats 'unsafe-inline' as a warning when a nonce or hash makes browsers ignore it, and credits 'strict-dynamic' and report-uri.

Missing Directives Named

A policy without object-src, base-uri, frame-ancestors or form-action is reported with the specific risk each gap leaves open, including when default-src already covers one of them.

HSTS, TLS and Mixed Content

HSTS max-age against the one-year preload threshold, the TLS handshake time, and every http:// subresource or form target that undermines an HTTPS page, listed with its selector.

Works on Staging and Behind Logins

Headers are read from the page you are already viewing, with your session, so internal tools and pre-production sites can be checked — no public URL for a scanner to reach.

Common Use Cases

Hardening a site before launch

Walk the checklist on the real page: confirm the CSP is enforced rather than report-only, HSTS is set for a year, and nothing is still loading over http://.

Checking a staging site no scanner can reach

Online header checkers need a public URL. This reads the page you are viewing, so a staging environment behind basic auth or a VPN is just as easy to check.

Reviewing a CSP you inherited

See at a glance whether a long policy actually restricts anything, or whether 'unsafe-inline' and a wildcard host have quietly turned it into decoration.

Tracking down mixed-content warnings

Find the exact image, script or form action still using http:// on an HTTPS page, with the element's selector, instead of hunting through the console.

Evidence for a security review

Copy a dated report of every header, its value and its verdict to attach to an audit, a pentest follow-up or a compliance questionnaire.

How to Use
1

Open Security & CSP

Click the Security & CSP icon in the DevSuite Pro dock. The check runs immediately and the summary shows how many headers passed, warned or are missing.

2

Read the header verdicts

The Headers tab lists each security header with its value and a verdict. Below it are the information-disclosure check and the document's CORS headers.

3

Review the policy

Open the CSP tab for the findings list, then the parsed directives. Red sources are failures, amber ones are worth a second look, green ones are what a strong policy uses.

4

Check the connection

The Connection tab covers HTTPS, the TLS handshake, HSTS and any mixed content. For the certificate itself, click the padlock in the address bar — no extension can read it.

5

Take the findings with you

Copy report produces a plain-text summary of every verdict, the CSP findings and any mixed content, ready for a ticket or a security review.

Ready to Try

Install DevSuite Pro for free and unlock 71+ developer tools for your browser.

Add to Chrome Add to Edge Add to FireFox