CSP Evaluator

#3.12 / 25 rate

CSP Evaluator

20,000 users

2020-04-16

Lukas Weichselbaum

Extension Information

5 star
24%
4 star
18%
3 star
0%
2 star
0%
1 star
58%

Supported Languages

Permissions

Hot Permissions

Description

CSP Evaluator is a tool that allows developers to check if a Content Security Policy (CSP) serves as mitigation against XSS attacks.

CSP Evaluator is a small tool that allows developers and security experts to check if a Content Security Policy (CSP) serves as a strong mitigation against cross-site scripting attacks. Reviewing CSP policies is usually a very manual process and most developers are not aware of CSP bypasses.
CSP Evaluator checks are based on a large-scale empirical study and are aimed to help developers to harden their CSP. This tool is provided only for the convenience of developers and Google provides no guarantees or warranties for this tool.

Reviews

Barbara Renowden
Barbara Renowden

I have a CSP but this doesn't detect it. So disappointed.

Helio Bentes
Helio Bentes

It doesn't detect meta CSP and it doesn't say anything about it on the description

Serghei Iakovlev
Serghei Iakovlev

For some unknown reason, when the extension was enabled, my browser sent additional requests to the sites. As a result, I lost a lot of hours debugging my site and trying to find the cause of the duplicate requests. As soon as I turned off the extension, the problem disappeared.

Similar extensions

Content Security Policy Override
Content Security Policy Override

https://rufflewind.com

Content Security Policy (CSP) Generator
Content Security Policy (CSP) Generator

https://csper.io

axe DevTools - Web Accessibility Testing
axe DevTools - Web Accessibility Testing

https://www.deque.com

CSP Tester
CSP Tester

oxdef

Always Disable Content-Security-Policy
Always Disable Content-Security-Policy

Unknown

Web Vitals
Web Vitals

addyosmani

Security-Header-Extension
Security-Header-Extension

ACNS_cybersecurity_interns

Caspr: Enforcer
Caspr: Enforcer

c0nrad

OWASP Penetration Testing Kit
OWASP Penetration Testing Kit

https://pentestkit.co.uk

Disable Content-Security-Policy
Disable Content-Security-Policy

Phil Grayson

Xdebug helper
Xdebug helper

Wrep

Google Analytics Debugger
Google Analytics Debugger

Google Analytics