security / security headers / content-security-policy
Security headers

Content-Security-Policy

A Content-Security-Policy controls exactly which scripts, styles and resources a browser is allowed to load on your site — your strongest defence against cross-site scripting.

Severity if missing
High
Category
Security headers
Standard
CSP Level 3

What it is

A Content-Security-Policy (CSP) is a response header that gives the browser an allow-list of trusted sources for content. Scripts, images, styles and other resources are only loaded if they come from a source you've explicitly permitted.

Anything not on the list — including malicious scripts an attacker manages to inject — is blocked by the browser before it can run.

Why it matters

Cross-site scripting (XSS) is one of the most common and damaging web vulnerabilities. If an attacker injects a script into your page, it runs with full access to your users' sessions. A well-configured CSP is the single most effective control against this — even if a script is injected, the browser refuses to execute it.

The risk
Without a CSP, any script that ends up on your page — through an injection flaw or a compromised third-party — runs freely, potentially stealing data or hijacking user sessions.

How Pentrawl checks it

Pentrawl checks your response headers for a Content-Security-Policy header. Its presence passes the check; its absence is flagged as an issue, since it leaves a major class of attack unmitigated.

How to fix it

Add a Content-Security-Policy header to your server. A good policy is specific to your site, so start restrictive and loosen it only where needed. The example below is a solid starting point.

Starting point
Content-Security-Policy: default-src 'self'; script-src 'self'; object-src 'none'
Check your domain's Content-Security-Policy in seconds
Pentrawl scans this and 20+ other security checks in one automated pass.
Scan your website →