What it checks
Whether the page sets a Content-Security-Policy header, and whether its script-src still allows inline scripts with 'unsafe-inline'.
A pass means: A Content Security Policy is set.
Possible findings
No Content Security Policy
Severity: LowConfidence: ConfirmedKind: Recommended hardening
What we found
The page does not set a Content-Security-Policy header.
Why it matters
A Content Security Policy limits where scripts and other content may load from. It greatly reduces the damage if a cross-site scripting bug is ever introduced.
How to fix it
Start with a report-only policy (Content-Security-Policy-Report-Only) to see what your pages load, then enforce a policy such as default-src 'self' plus the sources you need.
Content Security Policy allows inline scripts
Severity: LowConfidence: High confidenceKind: Recommended hardening
What we found
The Content Security Policy permits 'unsafe-inline' scripts without a nonce or hash.
Why it matters
Allowing inline scripts removes most of the protection a policy gives against cross-site scripting.
How to fix it
Move inline scripts into files, or use nonces or hashes, then remove 'unsafe-inline' from script-src.

