HTTP security
Content Security Policy checker
Read the Content-Security-Policy a site's home page sends, laid out directive by directive, and see whether it is enforced and whether it still lets inline scripts run.
What this checks
- The
Content-Security-Policyheader on the final HTTPS response for the home page, for the domain and itswww.name, or the subdomain entered. - Whether a policy is enforced. A
Content-Security-Policy-Report-Onlyheader on its own counts as no policy, because browsers only report against it. - Whether
script-src, ordefault-srcwhere there is noscript-src, contains'unsafe-inline'without a nonce, a hash or'strict-dynamic'. - Other
'unsafe-'sources, such as'unsafe-eval', are highlighted in the directive table but not judged.
What the result means
A Content Security Policy lists where a page may load scripts, styles, frames and other content from. If an attacker manages to inject markup into the page, the browser refuses to run script the policy does not allow, which limits what a cross-site scripting bug can do.
Most of that protection rests on script-src. 'unsafe-inline' lets any inline <script> block or event handler run, which is exactly what injected markup uses. Browsers ignore 'unsafe-inline' when a nonce or hash is also listed, so a policy with one is not flagged.
A pass means a policy is enforced and inline scripts are blocked. Either finding is low severity: a missing policy leaves the browser with no rules to apply, and an inline allowance keeps the rules for other content but gives up most of the protection against script injection.
How to fix common issues
No Content Security Policy
Start with a report-only policy (Content-Security-Policy-Report-Only) to see what your pages load, then enforce a policy such as default-src 'self' plus the sources you need.
Content Security Policy allows inline scripts
Move inline scripts into files, or use nonces or hashes, then remove 'unsafe-inline' from script-src.
Cyber Essentials and ISO 27001
Neither Cyber Essentials nor ISO 27001 names Content Security Policy. A policy is technical evidence for ISO/IEC 27001:2022 Annex A 8.26 (application security requirements): a defence that depends on how the application is built, so it belongs in the requirements for building or buying one.
The organisation decides whether its web applications must send a policy, who approves a new script source, and how a release that weakens the policy is caught. The header shows the policy in force today, not who agreed to it.
Scope and limitations
- It is not a full CSP audit. Only inline scripts are judged. Broad sources such as
*,https:or a whole CDN host,'unsafe-eval', and missing directives such asobject-srcorbase-uripass without comment. - Only the HTTP header is read. A policy set in a
<meta http-equiv>tag is not seen, and browsers ignoreframe-ancestorsand reporting directives there anyway. - It reads the home page. Other pages, especially ones behind a login, often send a different policy.
- It does not load the page in a browser, so it cannot tell whether the policy breaks anything or what it would report.
Related guides
Questions
- Should I start with Content-Security-Policy-Report-Only?
- Usually, yes. A report-only policy shows what an enforced one would block without breaking anything. Once the reports show only sources you expect, send the same policy as Content-Security-Policy.
- Why is unsafe-inline a problem?
- Injected script is almost always inline: a script tag or an event handler slipped into the page. Allowing unsafe-inline lets it run. A nonce or hash allows only the inline scripts you wrote.
- Can a Content Security Policy go in a meta tag?
- Partly. A meta tag policy works for most directives, but not frame-ancestors, report-uri or sandbox, and it applies only to content after the tag. The HTTP header is the stronger choice, and it is the one this checker reads.
Related security tools
- HTTP security headers checker - Check a site's HSTS, CSP, framing, content-type, referrer and permissions headers.
- Clickjacking protection checker - See whether other sites can frame a page: CSP frame-ancestors and X-Frame-Options.
- Cookie security checker - Check the Secure, HttpOnly and SameSite attributes of the cookies a home page sets.

