csp-auditor
csp-auditor copied to clipboard
Burp and ZAP plugin to analyse Content-Security-Policy headers or generate template CSP configuration from crawling a Website
CSP Auditor data:image/s3,"s3://crabby-images/77dac/77dac03385d8d885d085e4b49ffb2c50e15a15ff" alt="Build Status"
This plugin provides:
- a readable view of CSP Headers in Response Tab
- passive scan rules to detect weak CSP configuration
- a CSP configuration generator based on the Burp crawler or using manual browsing
This project is packaged as a ZAP and Burp plugin.
Download
Last updated : August 3th 2017
Screenshots
Passive rules and custom tab:
Configuration builder:
Building the plugin
Type the following command:
./gradlew build
or if you have already Gradle installed on your machine:
gradle build
Read more
For more context around Content-Security-Policy and how to apply it to your website see our blog posts on the topic:
- http://gosecure.net/2017/07/20/building-a-content-security-policy-configuration-with-csp-auditor
- https://gosecure.net/2016/06/28/auditing-csp-headers-with-burp-and-zap/