Content Security Policy Evidence Auditor
Pricing
from $2.80 / 1,000 page auditeds
Content Security Policy Evidence Auditor
Parse enforced and report-only Content-Security-Policy from response headers and HTML metadata into normalized directive and risk evidence.
Pricing
from $2.80 / 1,000 page auditeds
Rating
0.0
(0)
Developer
Michael Olmos
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
6 days ago
Last modified
Categories
Share
Parse enforced and report-only Content-Security-Policy from response headers and HTML metadata into normalized directive and risk evidence.
What is better
- Enforced, report-only, and meta policies kept distinct.
- Normalized directives and source tokens with exact evidence.
- Nonce, hash, wildcard, unsafe-inline, unsafe-eval, mixed-scheme, and missing-fallback findings.
- Deterministic grading without claiming penetration testing.
- Bounded SSRF-safe public fetching.
- Inputs, redirects, response bytes, and timeouts are bounded; memory is locked to 256 MB.
Charging
PAY_PER_EVENT uses a one-time Actor-start event plus page-audited. Only successful completed evidence rows are charged. Invalid inputs, network or protocol failures, and the OUTPUT summary are not charged.
Example input
{"pages": ["https://github.com/"],"maxPages": 1,"timeoutSecs": 20}
Output
The default dataset contains normalized evidence rows. The OUTPUT record reports submitted, unique, attempted, completed, failed, input-limited, and budget-limited counts without hiding partial failures. Findings are static page evidence, not legal, security, SEO, performance, mobile-readiness, or accessibility certification.