Input is processed only in the active browser tab's memory and is not sent to a ByteQuant server.
CSP Source Expression Tester
Review whether a URL matches a simple source-list and expose risky wildcards. Patterns are inspected without executing code; the result is not full SAST or proof of exploitability.
What does this tool do?
Review whether a URL matches a simple source-list and expose risky wildcards. Input is processed in this tab; review the disclosed limitations before using the result for an important decision.
- Input
- Only the text, values, or file you choose.
- Output
- Review whether a URL matches a simple source-list and expose risky wildcards.
- Verification
- Run the example, then review both the result and its limitation.
Input and output are not stored. The optional usage counter keeps only tool identity and count, never content.
Output comes from disclosed rules or browser APIs and needs independent review before high-impact use.
A result in three steps
- 01
Load the safe example or enter your own data.
- 02
Run it on-device and inspect errors, warnings, and metrics.
- 03
Validate the output in the target environment and with edge cases.
When is this tool useful?
- ✓ Auditable pre-publication quality control
- ✓ Repeatable team workflows
- ✓ Exposing errors and edge cases early
Automated output is a preliminary assessment. Do not use it alone for legal, financial, medical, or security-critical decisions.
Guides for this tool
Browser Security Pre-checks for CSP, SRI, JWT, and HTML
Review source policy, resource integrity, claim contracts, and risky HTML attributes with separate trust boundaries.
Read guide →Frequently asked questions
Does this tool send input to a server?+
No. Processing runs in this browser tab. Data leaves the page only when you choose to copy or download the result.
Is the result definitive?+
The tool produces consistent output from disclosed rules and browser APIs, but context, data quality, and method limitations can affect it. Verify high-impact decisions.
Is input saved?+
No. Tool input is not persisted. With consent, only tool identity and usage count may be kept on this device for personal shortcuts.