Skip to content

HTTP security configuration

What is a Content Security Policy?

Whether the page sets a Content-Security-Policy header, and whether its script-src still allows inline scripts with 'unsafe-inline'.

Part of the External Security Check. Free during the preview.

What it checks

Whether the page sets a Content-Security-Policy header, and whether its script-src still allows inline scripts with 'unsafe-inline'.

A pass means: A Content Security Policy is set.

Possible findings

No Content Security Policy

Severity: LowConfidence: ConfirmedKind: Recommended hardening

What we found

The page does not set a Content-Security-Policy header.

Why it matters

A Content Security Policy limits where scripts and other content may load from. It greatly reduces the damage if a cross-site scripting bug is ever introduced.

How to fix it

Start with a report-only policy (Content-Security-Policy-Report-Only) to see what your pages load, then enforce a policy such as default-src 'self' plus the sources you need.

Content Security Policy allows inline scripts

Severity: LowConfidence: High confidenceKind: Recommended hardening

What we found

The Content Security Policy permits 'unsafe-inline' scripts without a nonce or hash.

Why it matters

Allowing inline scripts removes most of the protection a policy gives against cross-site scripting.

How to fix it

Move inline scripts into files, or use nonces or hashes, then remove 'unsafe-inline' from script-src.

References