Automatically generate a CSP for your site.
cspresso crawls up to N same‑origin pages with headless Chromium (Playwright), watches the assets that load,
and emits a draft Content-Security-Policy header with evidence to review.
pipx install cspresso
cspresso https://mig5.net --max-pages 10
# visited: https://mig5.net/
Content-Security-Policy: default-src 'self'; script-src 'self' https://cdn.jsdelivr.net; ...;
How it works
cspresso lets the browser do the hard part: execute the page, watch what it loads, and distill origins into directives.
It uses Playwright (a tool designed to run a browser in 'headless' mode, originally to help automate performing frontend testing of websites) to visit the website in the background and learn what directives of a Content-Security Policy would be needed in order to set such a header and still have the website function properly.
It can also evaluate a provided CSP against a site and report observed violations during the selected crawl, before you ship it. A completed scan is not a guarantee that every application flow is covered.
--max-pages same-origin pages and let the app’s JS run.Popular flags
A few options that tend to matter in real deployments.
connect-src permissions.upgrade-insecure-requests in the proposed policy.Install
pipx, pip, Poetry, or a standalone AppImage from Releases.
# Recommended
pipx install cspresso
# Or plain pip (use a venv)
pip install cspresso
~/.cache/cspresso/pw-browsers on Linux. Chromium sandboxing is enabled by default.
--browsers-path or PLAYWRIGHT_BROWSERS_PATH.
# From the source checkout, Poetry >=2.2,<3
poetry sync --with dev
poetry run cspresso https://example.com/ --json
poetry run playwright install-deps chromium. --with-deps applies when installing missing browser binaries.
chmod +x CSPresso.AppImage
./CSPresso.AppImage https://example.com \
--browsers-path "$HOME/.cache/cspresso/pw-browsers"
--browsers-path if needed.
54A91143AE0AB4F7743B01FE888ED1B423A3BC99).