Content Security Policy Evidence Auditor avatar

Content Security Policy Evidence Auditor

Pricing

from $2.80 / 1,000 page auditeds

Go to Apify Store
Content Security Policy Evidence Auditor

Content Security Policy Evidence Auditor

Parse enforced and report-only Content-Security-Policy from response headers and HTML metadata into normalized directive and risk evidence.

Pricing

from $2.80 / 1,000 page auditeds

Rating

0.0

(0)

Developer

Michael Olmos

Michael Olmos

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

6 days ago

Last modified

Share

Parse enforced and report-only Content-Security-Policy from response headers and HTML metadata into normalized directive and risk evidence.

What is better

  • Enforced, report-only, and meta policies kept distinct.
  • Normalized directives and source tokens with exact evidence.
  • Nonce, hash, wildcard, unsafe-inline, unsafe-eval, mixed-scheme, and missing-fallback findings.
  • Deterministic grading without claiming penetration testing.
  • Bounded SSRF-safe public fetching.
  • Inputs, redirects, response bytes, and timeouts are bounded; memory is locked to 256 MB.

Charging

PAY_PER_EVENT uses a one-time Actor-start event plus page-audited. Only successful completed evidence rows are charged. Invalid inputs, network or protocol failures, and the OUTPUT summary are not charged.

Example input

{
"pages": [
"https://github.com/"
],
"maxPages": 1,
"timeoutSecs": 20
}

Output

The default dataset contains normalized evidence rows. The OUTPUT record reports submitted, unique, attempted, completed, failed, input-limited, and budget-limited counts without hiding partial failures. Findings are static page evidence, not legal, security, SEO, performance, mobile-readiness, or accessibility certification.