Content Security Policy Evaluator - Online Hash & Nonce Check
Test if a script or style will be allowed by a given CSP. Compute hash/nonce. Strengthen your site’s defense against XSS. Local.
UD5 Toolkit
Analyze HSTS, CSP, X-Frame-Options & more in seconds. Detect missing security headers and fix your website’s configuration.
| Security Header | Status | Value / Recommendation | Risk |
|---|
Test if a script or style will be allowed by a given CSP. Compute hash/nonce. Strengthen your site’s defense against XSS. Local.
Look at HTTP headers and JavaScript objects to guess which browser extensions might be installed. For awareness.
Paste a JSON Web Token and decode its header and payload. Verify signature if you provide the secret. Fully local.
Paste a user agent string to get a human-readable breakdown of browser, operating system, and device. See your own current agent info automatically.
Build an iframe with different sandbox flags and see live which features are blocked. For secure embedding.
Paste a potential XSS vector and see if it executes in a sandboxed iframe. For security researchers and education.
Compare two text blocks and highlight differences line by line. Ideal for code review and document revisions. All diffs computed locally for privacy.
Enter a URL and see the full redirect chain with status codes and response times. Also validates against your chosen rule.
Browse Unicode by block: Latin, Cyrillic, CJK, Emoticons. See characters and copy with a click. Full reference.
Paste a robots.txt file and validate its syntax. See if a specific user‑agent can access a path. Essential for webmasters.
Design a clean, professional email signature with your photo, links, and disclaimers. Copy the HTML to use in Gmail/Outlook.
Type your name and create a stylized ASCII text banner for email signatures or forum posts. Choose a font style.
See your monitor's color depth and pixel depth. Detect if HDR or wide gamut is available using media queries.
Paste two JSON objects and find the structural differences with side‑by‑side highlighted output. Indispensable for API debugging.
Paste an HTML snippet and see how a screen reader might interpret it. Highlights missing alt texts and ARIA misuses. Educational.
Create a polished HTML email signature with your photo, links, and company details. Live preview and copy HTML to clipboard. Works with Gmail, Outlook, Apple Mail.
Create custom traceable handwriting worksheets with name or sentence. Print in dotted font. Great for teachers and parents.
Compose messages with bold, italic, links, and code. See the raw HTML or Markdown for your Telegram bot API calls.
Test required, pattern, minlength etc. See validity states and custom error messages. Learn browser‑native validation.
Design borders with linear or conic gradients. Supports border‑image and background‑clip methods. Copy optimized CSS.
Parse a URL's query string into a key-value table, or build a query string from parameters. Perfect for API testing and web development.
Graph a cubic‑bezier or steps easing function and see a bouncing ball animation using it. Copy the CSS timing‑function.
Simulate a traceroute by entering a destination IP. Learn about AS paths and latency. Does not send real packets; educational visualisation.
Paste a website's HTML and see which text is only visible to screen readers (e.g., .sr‑only). Preview the accessible layer.
Enter HTML with aria-labels and see what a screen reader would announce. Simulates common patterns. Local educational tool.
Draw pixel art with a grid, color palette, and eraser. Export as PNG. Perfect for game developers and hobbyists.
Draw walls on a grid and watch A*, Dijkstra, or BFS find the shortest path. Interactive animation. Learn graph traversal.
Check if the browser has captured the beforeinstallprompt event. Understand why your PWA is (or isn't) installable.
Check if a password appears in the Have I Been Pwned database using k‑Anonymity. Only the first 5 characters of the hash are sent.
Enter an API URL and quickly check its HTTP status code and response time. See response headers and body. Browser fetch.