Page Security

CSP script safety check

Whether your Content-Security-Policy still lets injected inline scripts and eval() run, which undoes most of what CSP is for.

Check this on your own domain now. It is free with a DomainGuard account, reads only public records, and gives you a report you can send to whoever runs your website.

What we look at

We read the script-src rule in your Content-Security-Policy and check for 'unsafe-inline' and 'unsafe-eval', and whether nonces or hashes are used instead.

Why it matters to your business

Most attacks that inject code into a website inject it inline. A policy that allows 'unsafe-inline' looks protective on a checklist but lets exactly that code run in your visitors' browsers, where it can read forms and steal logins.

How to fix it

  1. Move inline scripts into files, or give each one a nonce or hash in the policy.
  2. Remove 'unsafe-inline' and 'unsafe-eval' from script-src once nothing depends on them.
  3. Run the policy as Report-Only first to see what would break.

If you would rather not touch DNS or server settings yourself, forward this page and your report to whoever manages your website, or ask us to do it.

Keep an eye on it

A one-off check tells you how things stand today. On Starter and up, DomainGuard re-checks the domains it watches every day and alerts you in the app when something important changes, so you hear about it before a customer does.