Headless Crawling
Automatically crawl your site with a deny-all report-only CSP, capturing every violation. Playwright-powered with configurable depth, page limits, and authentication support.
Generate production-ready CSP headers automatically
Content Security Policy headers are one of the strongest browser-side defences against XSS and data injection attacks, but writing them by hand is tedious and error-prone. CSP Analyser automates the process:
Content-Security-Policy-Report-Only headerThe tool runs entirely on your local machine. No data is sent to any external service.