Visually configure each CSP directive using toggles and source checkboxes. Preview the generated header string in real-time and get security analysis for every setting.
Related free tools
Paste response headers and grade CSP, HSTS, X-Frame-Options and more.
Check Access-Control headers for wildcard origins, credential leaks and reflection bugs.
Pin third-party scripts your CSP allows so a compromised CDN cannot swap them.
Read next
The attack CSP exists to stop — reflected, stored and DOM-based — with the defences that work at each layer.
AquilaX DAST checks the Content-Security-Policy your production site actually serves on every release, flags unsafe-inline creeping back in, and finds the XSS sinks in code that the policy is meant to contain.
Free plan is permanent · unlimited scans · GitHub, GitLab, Bitbucket & Azure DevOps