Free Tool · Client-Side Only

Content Security Policy
Builder.

Visually configure each CSP directive using toggles and source checkboxes. Preview the generated header string in real-time and get security analysis for every setting.

📋

Generated CSP Header

Configure directives below to generate your CSP…

Quick Presets

⚙️

Configure Directives

🔍

Security Analysis

Related free tools

Read next

What is XSS (cross-site scripting)?

The attack CSP exists to stop — reflected, stored and DOM-based — with the defences that work at each layer.

A policy is only as good as its deployment

Catch the deploy that
quietly drops your CSP.

AquilaX DAST checks the Content-Security-Policy your production site actually serves on every release, flags unsafe-inline creeping back in, and finds the XSS sinks in code that the policy is meant to contain.

Free plan is permanent · unlimited scans · GitHub, GitLab, Bitbucket & Azure DevOps