CSP Auditor

CSP Auditor

#Application Protection#Application Security

Cross-site scripting labs for web application security enthusiasts

Visit Website

This plugin offers a clear view of CSP Headers

This plugin offers a clear view of CSP Headers in the Response Tab. It includes passive scan rules to identify weak CSP configurations and provides a CSP configuration generator that works based on the Burp crawler or through manual browsing.

The project is packaged as a ZAP and Burp plugin

The project is packaged as a plugin for both ZAP and Burp.

For More Context on Content-Security-Policy

To gain a deeper understanding of Content-Security-Policy and learn how to implement it on your website, check out their informative blog posts on the subject: [Building a Content Security Policy Configuration with CSP Auditor](http://gosecure.net/2017/07/20/building-a-content-security-policy-configuration-with-csp-auditor) and [Auditing CSP Headers with Burp and ZAP](https://gosecure.net/2016/06/28/auditing-csp-headers-with-burp-and-zap/).