Skip to content

HTTP security

Content Security Policy checker

Read the Content-Security-Policy a site's home page sends, laid out directive by directive, and see whether it is enforced and whether it still lets inline scripts run.

Checked from Ironfang Security's scanner address with the same low-impact limits as a scan. Nothing you enter is kept.

What this checks

What the result means

A Content Security Policy lists where a page may load scripts, styles, frames and other content from. If an attacker manages to inject markup into the page, the browser refuses to run script the policy does not allow, which limits what a cross-site scripting bug can do.

Most of that protection rests on script-src. 'unsafe-inline' lets any inline <script> block or event handler run, which is exactly what injected markup uses. Browsers ignore 'unsafe-inline' when a nonce or hash is also listed, so a policy with one is not flagged.

A pass means a policy is enforced and inline scripts are blocked. Either finding is low severity: a missing policy leaves the browser with no rules to apply, and an inline allowance keeps the rules for other content but gives up most of the protection against script injection.

How to fix common issues

No Content Security Policy

Start with a report-only policy (Content-Security-Policy-Report-Only) to see what your pages load, then enforce a policy such as default-src 'self' plus the sources you need.

More in the Content Security Policy check reference

Content Security Policy allows inline scripts

Move inline scripts into files, or use nonces or hashes, then remove 'unsafe-inline' from script-src.

More in the Content Security Policy check reference

Cyber Essentials and ISO 27001

Neither Cyber Essentials nor ISO 27001 names Content Security Policy. A policy is technical evidence for ISO/IEC 27001:2022 Annex A 8.26 (application security requirements): a defence that depends on how the application is built, so it belongs in the requirements for building or buying one.

The organisation decides whether its web applications must send a policy, who approves a new script source, and how a release that weakens the policy is caught. The header shows the policy in force today, not who agreed to it.

Scope and limitations

Related guides

Questions

Should I start with Content-Security-Policy-Report-Only?
Usually, yes. A report-only policy shows what an enforced one would block without breaking anything. Once the reports show only sources you expect, send the same policy as Content-Security-Policy.
Why is unsafe-inline a problem?
Injected script is almost always inline: a script tag or an event handler slipped into the page. Allowing unsafe-inline lets it run. A nonce or hash allows only the inline scripts you wrote.
Can a Content Security Policy go in a meta tag?
Partly. A meta tag policy works for most directives, but not frame-ancestors, report-uri or sandbox, and it applies only to content after the tag. The HTTP header is the stronger choice, and it is the one this checker reads.

Related security tools