CSP Violation-Report Analyzer

Group supplied CSP violation reports by directive and disposition while omitting URL details and samples.

Inputs stay on your device No sign-up Free to use
How this works

The tool runs in this browser. Your file or text is not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Privacy details

Analyze CSP reports controls

Up to 1 MiB and 1,000 events. Paste the Reporting API array or a legacy {"csp-report": ...} object. Reports remain in your browser.

Processed in your browser. Your inputs stay on this device.

Showing a generated example. Generate again for a new result.

How to use CSP Violation-Report Analyzer

  1. Supply the violation reports as json using the supported input described beside the controls.
  2. Review the selected options and the declared scope, then run the csp report analyzer.
  3. Read the result and unresolved findings before downloading or sharing a report. The original input is not changed.

Example: CSP Violation-Report Analyzer

Group uploaded violation reports, suppress sensitive URL values and compare directives. This example uses synthetic public data.

You add
Violation reports as JSON: [ { "type": "csp-violation", "body": { "documentURL": "https://shop.example.com/orders/checkout?cart=42&token=abc", "referrer": "https://search.example.org/results?q=secret", "blockedURL": "https://cdn.tracker.example/pixel.gif?id=9911", "effectiveDirective": "img-src", "disposition": "enforce", "lineNumber": 12, "columnNumber": 4, "statusCode": 200 } }, { "type": "csp-violation", "body": { "documentURL": "https://shop.example.com/orders/checkout?cart=42&token=abc", "blockedURL": "inline", "effectiveDirective": "script-src", "disposition": "report", "lineNumber": 40, "columnNumber": 1 } } ]
You get
2 reports across 2 directives: 1 enforcing, 1 report-only. img-src | 1 | 0 | https://cdn.tracker.example script-src | 0 | 1 | inline

Options

Report format
Supply a supported legacy CSP report or Reporting API collection. The analyzer does not collect reports from a live site.
Disposition
Review enforcement and report-only groups separately before deciding which declared directive needs attention.

Supported inputs and limits

Bounded supported report formats only. No URL fetch, live policy discovery, exploitation test or proof of report authenticity.

Where your input is processed

This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Reports are observations supplied by someone else

An enforcing event and a report-only event have different meanings, so keep their groups separate. Reports can be incomplete or forged and do not establish a site’s current policy. URL values are reduced to the supported scheme/origin representation; samples and arbitrary extensions are omitted rather than copied into exports.

Questions about CSP Violation-Report Analyzer

Are URL tokens exported?

Detailed path, query, fragment and credential values are omitted by the supported sanitization.

Does a report prove a current policy?

No. Supplied reports can be stale, partial or forged.

Are script samples included?

No. Samples and unsupported extensions are omitted from the report.

Project manager: Tony Hines · Content updated 4 October 2026 · Report a problem