Security

CSRF Risk Checker

Analyze forms and APIs for CSRF vulnerabilities and get remediation guidance.

Last reviewed by the Radiatus Cloud team

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

Check your CSRF protections

Cross-site request forgery tricks a logged-in user’s browser into making an unwanted request to your application, which the application trusts because it comes with the user’s session. This checker helps you review whether your own application has the protections that prevent it.

Why CSRF works

Because a browser automatically sends a user’s cookies with requests to a site, a malicious page can cause the user’s browser to submit a request to your application that acts as the user, without their intent. State-changing actions without CSRF protection are exposed.

The defence

The defences are anti-CSRF tokens that a forged request cannot supply, the SameSite cookie attribute that limits cross-site cookie sending, and checking the request origin. Reviewing your protections confirms state-changing actions are defended. This is for defensive assessment and education around systems you own or protect, or for authorised security testing and awareness, not for targeting others. It runs entirely in your browser, so nothing you enter is uploaded, which matters when the input concerns your own security posture.

Related tools

  • Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
  • Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
  • Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
  • Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.

Frequently Asked Questions

What is CSRF?

An attack that tricks a logged-in user’s browser into making an unwanted request to your application, which trusts it because it carries the user’s session.

How do I prevent CSRF?

Use anti-CSRF tokens that a forged request cannot supply, set the SameSite cookie attribute, and check the request origin on state-changing actions.

Why does CSRF work?

Because browsers automatically send a user’s cookies with requests, so a malicious page can cause a request that acts as the logged-in user.

Is this for my own application?

Yes. It is defensive review of whether your own application protects its state-changing actions against forged cross-site requests.

Is my input uploaded?

No. It runs entirely in your browser.

Privacy & Security

Analysis done locally.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.