Content-Security-Policy
A Content-Security-Policy controls exactly which scripts, styles and resources a browser is allowed to load on your site — your strongest defence against cross-site scripting.
What it is
A Content-Security-Policy (CSP) is a response header that gives the browser an allow-list of trusted sources for content. Scripts, images, styles and other resources are only loaded if they come from a source you've explicitly permitted.
Anything not on the list — including malicious scripts an attacker manages to inject — is blocked by the browser before it can run.
Why it matters
Cross-site scripting (XSS) is one of the most common and damaging web vulnerabilities. If an attacker injects a script into your page, it runs with full access to your users' sessions. A well-configured CSP is the single most effective control against this — even if a script is injected, the browser refuses to execute it.
How Pentrawl checks it
Pentrawl checks your response headers for a Content-Security-Policy header. Its presence passes the check; its absence is flagged as an issue, since it leaves a major class of attack unmitigated.
How to fix it
Add a Content-Security-Policy header to your server. A good policy is specific to your site, so start restrictive and loosen it only where needed. The example below is a solid starting point.
Content-Security-Policy: default-src 'self'; script-src 'self'; object-src 'none'