CSP Generator Extension for Chrome and Firefox
The Script Sentinel CSP generator extension starts a free scan of the public URL in your active tab. Review the generated Content Security Policy and copy the candidate for testing. No account is required for the free extension workflow.
Generate a CSP from your active tab
- Install the extension for your browser and open a public HTTP or HTTPS page you are authorized to scan.
- Open the extension, review the target URL and scan options, and choose a crawl depth of 1–3 public pages.
- Click Generate CSP. The extension sends the URL and selected options to Script Sentinel's scanner. Keep the Chrome popup open until it completes.
- Review the result, warnings, and scan coverage. Copy the candidate and test it with the Content-Security-Policy-Report-Only header before enforcement.
The extension displays copyable output. For the full website editor, open the CSP scanner and generator and scan the URL there. Use header examples by platform when configuring delivery.
Chrome and Firefox behavior
Chrome runs the scan request from its popup, so keep that popup open. Firefox runs an explicitly started request in its background script, allowing the scan to finish after the popup closes.
Firefox can restore a completed result when local history is enabled. With history disabled, a closed popup has no saved result to restore.
What does the scanner see?
The backend visits the public URL; it does not scan your active tab's live DOM or use your login cookies. A signed-in page in your browser may look different to the scanner. Browser settings pages and local or private-network destinations are not supported scan targets.
A generated policy reflects reached pages and states. Review conditional resources and exercise representative user flows during report-only testing.
Where is scan history stored?
Optional extension-local history keeps up to five recent results and is enabled by default. You can clear it or turn it off. The extension starts scans when you request them; it does not collect background browsing history.
Scanning sends the chosen public URL and options to Script Sentinel. Read the privacy policy for service and extension data handling.
Does the extension install the policy?
No. Copying a CSP does not configure your server or enable enforcement. You choose where to deploy the policy and test the resulting headers. Premium monitoring is a separate website service; a paid website session does not raise the extension's scan limit.