Review homepage CSP and report-only status
Check key directives such as default-src, script-src, and object-src plus policy mode.
Open exampleInspect a URL's Content-Security-Policy and Report-Only headers, then flag risky default-src, script-src, object-src, base-uri, and frame-ancestors settings.
The result will appear here as structured cards.
Short, high-intent examples that are easy to open, share, and understand for search engines and AI systems.
Check key directives such as default-src, script-src, and object-src plus policy mode.
Open exampleSpot-check script-src, frame-ancestors, and mixed-content hardening signals.
Open exampleUse the asset and third-party script topic to review script-src, connect-src, frame-ancestors, and report-only rollout risk.
Open exampleUse the website-check topic to review script-src, frame-ancestors, report-only posture, and dual-origin policy consistency.
Open exampleConfirm whether the AI crawl-file has CSP, content-type, cache, and security-header signals that support stable search and AI fetching.
Open exampleCheck whether the crawl-rule file has clear CSP, content-type, cache, and security-header signals for search and AI fetchers.
Open exampleCheck whether the sitemap submission file has clear CSP, XML content type, cache, and security-header signals for search systems.
Open exampleCheck CSP, security headers, content type, and cache signals for the Baidu verification file so search systems can read it reliably.
Open exampleCheck CSP, security headers, XML content type, and cache signals for the Bing verification file.
Open exampleCheck CSP, security headers, content type, and cache signals for the IndexNow key file before relying on push diagnostics.
Open exampleConfirm the health endpoint's CSP, content type, cache, and security headers stay aligned with post-release crawl-entry QA.
Open exampleThese notes help users understand the results and help search engines and AI systems understand the tool.
It helps you inspect or process this value and get a readable result quickly.
Local tools run in the browser when possible. Server-side checks only use the input needed to complete the lookup.
Start with `Content-Security-Policy-Report-Only` to collect breakage, then enforce incrementally. Prioritize script-src, object-src, frame-ancestors, and base-uri hardening first.
`unsafe-inline` broadens script execution paths and weakens XSS controls. Prefer nonce/hash-based script control with narrow source allowlists.
List the real script, API, iframe, image, and reporting domains first, then review script-src, connect-src, img-src, frame-src, and frame-ancestors. Use Report-Only for new tags before enforcing the policy.
Based on this query: https://chakan.com/80dd502e8538faf8d62ceed13d8e92d9.txt