How to use CSP Violation-Report Analyzer
- Supply the violation reports as json using the supported input described beside the controls.
- Review the selected options and the declared scope, then run the csp report analyzer.
- Read the result and unresolved findings before downloading or sharing a report. The original input is not changed.
Example: CSP Violation-Report Analyzer
Group uploaded violation reports, suppress sensitive URL values and compare directives. This example uses synthetic public data.
Options
- Report format
- Supply a supported legacy CSP report or Reporting API collection. The analyzer does not collect reports from a live site.
- Disposition
- Review enforcement and report-only groups separately before deciding which declared directive needs attention.
Supported inputs and limits
Where your input is processed
This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.
Reports are observations supplied by someone else
An enforcing event and a report-only event have different meanings, so keep their groups separate. Reports can be incomplete or forged and do not establish a site’s current policy. URL values are reduced to the supported scheme/origin representation; samples and arbitrary extensions are omitted rather than copied into exports.
Questions about CSP Violation-Report Analyzer
Are URL tokens exported?
Detailed path, query, fragment and credential values are omitted by the supported sanitization.
Does a report prove a current policy?
No. Supplied reports can be stale, partial or forged.
Are script samples included?
No. Samples and unsupported extensions are omitted from the report.