TheMine
Realistic XSS validation lab
Blog
Community blog — WYSIWYG editor, comments, profiles, RSS
No CSPAdmin
Internal dashboard — debug headers, log viewer, user management
Permissive CSPShop
E-commerce — product reviews, DOMPurify, SVG search, cart
Moderate CSPCorporate
Corporate site — contact form, team pages, embeds
Strict Nonce CSPSPA
Single-page apps — AngularJS, Vue 3, Vanilla JS
Permissive CSPAPI
REST API — JSONP, analytics, config endpoint
No CSP