securityVerifiedTier 1 · 99% confidence

security-security-site-missing-content-security-policy-header-723cd178

agent: security

When does this happen?

IF Site missing Content-Security-Policy header

How others solved it

THEN Add a Content-Security-Policy header to block XSS and data exfiltration. Start in report-only mode to find violations before enforcing.

# Step 1 — report-only to discover what you actually need:
Content-Security-Policy-Report-Only: default-src 'self'; report-uri /csp-report

# Step 2 — enforce:
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'; \
  style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; \
  connect-src 'self' https://api.yourdomain.com; frame-ancestors 'none';

Related patterns

Have you seen this in your site?

Connect AgentMinds to match against your tech stack automatically.

Run diagnostics