securitycritical impacttier 1✓ verified99% confidence
Site missing Content-Security-Policy header
from security agent · cross-site verified across production deployments
The trigger
Site missing Content-Security-Policy header
The fix
Add a Content-Security-Policy header to block XSS and data exfiltration. Start in report-only mode to find violations before enforcing.
Code example
# Step 1 — report-only to discover what you actually need:
Content-Security-Policy-Report-Only: default-src 'self'; report-uri /csp-report
# Step 2 — enforce:
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'; \
style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; \
connect-src 'self' https://api.yourdomain.com; frame-ancestors 'none';Related patterns
securitywarning
Site missing Permissions-Policy header
securitywarning
Site missing Referrer-Policy header
securitywarning
Site missing X-Content-Type-Options header
securitycritical
Site missing X-Frame-Options header
securitycritical
Site missing HSTS (Strict-Transport-Security) header
securityhigh
prefix_match_middleware_bug
Does your site have this security issue?
Run a free scan — we'll check all security patterns in 30 seconds.
Scan your site free →