Skip to content
vaultocean
alphaTypeScript

CSPy

A browser extension that audits the CSP and security headers of any site you visit and explains, in plain language, what an attacker could do with the gaps.

Capabilities

cspheadersbrowseraudit
install

# Install from Chrome Web Store (link above)

# Open DevTools → CSPy tab on any page

# Or use the inline analyzer below

$

Contribute · earn fathoms

Open issues are labelled good-first-issue. Merge a pull request and earn +100ƒ — it lands directly on your Depth profile.

Real-time audit

Inspects every page you visit as you browse, not just when you remember to run a scan.

Plain-English explanations

Each gap explains what an attacker could actually do — not just which header is missing.

Export-ready

One-click copy of the full CSP report for inclusion in a pentest or bug bounty submission.

Inline CSP analyzer — paste and inspect

or try an example: