Content Security Policy
Silktide checks that every page declares a Content Security Policy, a standard security measure that tells browsers which sources of scripts, images, and other content the page is allowed to use.
A Content Security Policy (CSP) is delivered as an or a meta tag, for example:
Content-Security-Policy: default-src 'self'; script-src 'self' scripts.example.com
This example tells the browser to load content only from your own domain, plus scripts from one trusted host.
Why this matters
Without a CSP, a page runs whatever it is given. If an attacker manages to inject a script - through a compromised third-party tag, a vulnerable comment field, or a hijacked advertising network - the browser executes it with full access to the page, including anything your visitors type. This class of attack, cross-site scripting, remains one of the most common ways websites are compromised.
A CSP is the browser-side safety net: injected content from an unapproved source simply does not load. It also documents which third parties your pages talk to, which helps when demonstrating compliance with privacy regulations such as .
How to fix it
- List the legitimate sources your pages load content from: your own domain, your , analytics, fonts, and embedded media.
- Write a policy allowing only those sources. Start strict, for example
default-src 'self', and add specific sources per content type (script-src,img-src,style-src) as needed. - Configure your web server, hosting platform, or CDN to send the policy as
the
Content-Security-Policyheader on every page. If you cannot change headers, a<meta http-equiv="Content-Security-Policy">tag in the page head also works, though the header is preferred. - Test before enforcing: send the policy as
Content-Security-Policy-Report-Onlyfirst, and watch the browser console for content that would have been blocked. Note that this check looks for the enforcing header, so a report-only policy does not pass it.
How Silktide tests this
- Load each page and collect its HTTP headers along with any
http-equivmeta tags in the page, which browsers treat the same way. - Look for a
Content-Security-Policyvalue in either place. - Report the page if neither is present or the value is empty.
- Silktide does not judge the quality of the policy - only that one exists.
Troubleshooting
I set a policy but the check still fails
Confirm the header appears on the exact pages being scanned - policies are sometimes only configured for the homepage or one virtual host. You can see the headers a page returns in your browser's developer tools, under the Network tab.
Will a CSP break my website?
A policy that is too strict can block your own scripts or styles. This is
why testing with Content-Security-Policy-Report-Only first is strongly
recommended - it reports violations without blocking anything.