Skip to content
SilktideHelp

Content Security Policy

Silktide checks that every page declares a Content Security Policy, a standard security measure that tells browsers which sources of scripts, images, and other content the page is allowed to use.

A Content Security Policy (CSP) is delivered as an or a meta tag, for example:

Content-Security-Policy: default-src 'self'; script-src 'self' scripts.example.com

This example tells the browser to load content only from your own domain, plus scripts from one trusted host.

Why this matters

Without a CSP, a page runs whatever it is given. If an attacker manages to inject a script - through a compromised third-party tag, a vulnerable comment field, or a hijacked advertising network - the browser executes it with full access to the page, including anything your visitors type. This class of attack, cross-site scripting, remains one of the most common ways websites are compromised.

A CSP is the browser-side safety net: injected content from an unapproved source simply does not load. It also documents which third parties your pages talk to, which helps when demonstrating compliance with privacy regulations such as .

How to fix it

  1. List the legitimate sources your pages load content from: your own domain, your , analytics, fonts, and embedded media.
  2. Write a policy allowing only those sources. Start strict, for example default-src 'self', and add specific sources per content type (script-src, img-src, style-src) as needed.
  3. Configure your web server, hosting platform, or CDN to send the policy as the Content-Security-Policy header on every page. If you cannot change headers, a <meta http-equiv="Content-Security-Policy"> tag in the page head also works, though the header is preferred.
  4. Test before enforcing: send the policy as Content-Security-Policy-Report-Only first, and watch the browser console for content that would have been blocked. Note that this check looks for the enforcing header, so a report-only policy does not pass it.

How Silktide tests this

  1. Load each page and collect its HTTP headers along with any http-equiv meta tags in the page, which browsers treat the same way.
  2. Look for a Content-Security-Policy value in either place.
  3. Report the page if neither is present or the value is empty.
  4. Silktide does not judge the quality of the policy - only that one exists.

Troubleshooting

I set a policy but the check still fails

Confirm the header appears on the exact pages being scanned - policies are sometimes only configured for the homepage or one virtual host. You can see the headers a page returns in your browser's developer tools, under the Network tab.

Will a CSP break my website?

A policy that is too strict can block your own scripts or styles. This is why testing with Content-Security-Policy-Report-Only first is strongly recommended - it reports violations without blocking anything.

Learn more

Last updated

Was this page helpful?

Content Security Policy | Silktide Help