LEARN · CSP
Content-Security-Policy (CSP)
What a CSP is, why unsafe-inline weakens it and how to start with a restrictive policy.
WHAT IT IS
CSP is a header telling the browser where your site may load scripts, styles, images or frames from. Anything not allowed is blocked. With frame-ancestors you also decide who may embed your site.
WHY IT MATTERS
If someone manages to inject code into your site (XSS), a good CSP stops it from running or sending data out. It does not replace fixing bugs: it limits the damage.
COMMON MISTAKES
- Allowing 'unsafe-inline' or 'unsafe-eval' for scripts (it cancels most of the protection).
- Huge domain allow-lists "just in case".
- Enabling it all at once without testing: start with Content-Security-Policy-Report-Only.
EXAMPLE
Content-Security-Policy: default-src 'self'; img-src 'self' data:; object-src 'none'; base-uri 'self'; frame-ancestors 'self'
HOW WE CHECK IT
- HDR_CSP v1.0.0 — Whether a CSP exists and whether it allows `unsafe-inline` or `unsafe-eval` for scripts.
- HDR_CLICKJACKING v1.0.0 — That embedding the site in foreign frames is prevented (`X-Frame-Options` or CSP `frame-ancestors`).