Hash final bytes, then re-run after every build change
The file path can preserve strict UTF-8 and line endings for the supplied final HTML. Browser text controls can normalize pasted line endings, and direct text cannot prove how a build inserts it. Review-only hashes are labeled rather than claimed authoritative.
Inline script data keeps literal entity text: this scanner does not HTML-decode entities. Leading and trailing whitespace are hashed. Minification, formatting, line-ending conversion, asset fingerprinting, or any import-map byte change requires a new hash.
Value-free local outcome
Hash plan
Anonymous import-map blocks
Policy fragment
Use script-src-elem when that directive exists; otherwise script-src is the script-element fallback. If neither exists, this tool proposes script-src-elem but does not design the complete policy or evaluate default-src.
Fixed findings
Fixed build checklist
Bounded semantics and non-goals
HTML mode scans only inline <script type="importmap"> blocks. External src, malformed or unclosed tags, multiple candidates, duplicate attributes, entity-encoded attributes, and unsupported attribute shapes produce fixed error or review findings. JSON checks stop at parseability and top-level imports/scopes object shape.
This tool does not fetch an endpoint, modify a build pipeline, integrate a nonce or server, design a full CSP, guarantee import-map or CSP browser support, or reproduce a browser HTML/CSP engine. The report contains hashes and fixed metadata, never entered HTML, JSON, CSP, specifiers, or URLs.
Optional manual review
Final import-map hash check — USD 19
One final HTML file, one CSP, a hash manifest and policy checklist, and one revision.
Email winni80@gmail.com. In the first email, do not send a source archive, proprietary HTML, import-map content, URL, or token. Send only the value-free report and framework/build-tool version.
There is no payment link. This offer and contact address are not evidence of an inquiry, lead, customer, payment, or revenue.