Skip to main content

Headers

Content Security Policy: the header that stops most XSS attacks dead.

Published 2026-05-12 · Last updated 2026-05-12 · Vantyris editorial

Content Security Policy (CSP) is a header that tells the browser which sources your page may load scripts from, and the same for styles, fonts and images. Without it, a script injected through a compromised plugin or a clever XSS bug can run and send your visitors' data wherever the attacker likes. With it, the browser refuses to run anything from a source you haven't explicitly allowed. CSP is the single header that prevents the most common class of website attacks.

What this means for your business

How to fix

Start with Content-Security-Policy-Report-Only (observe mode) and watch the browser report violations for a week. Fix the policy until the reports are clean, then switch to the enforcing Content-Security-Policy header.

  1. Audit what your site already loads. Open your site with Chrome DevTools on the Network tab. Write down every outside domain the page loads anything from (scripts, styles, fonts, images, frames). The common ones are Google Fonts, Stripe, your CDN, analytics tools and embedded YouTube.
  2. Draft a basic policy. A reasonable starting point: default-src 'self'; script-src 'self' https://js.stripe.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: https:; font-src 'self' https://fonts.gstatic.com; frame-ancestors 'none'; form-action 'self'. Adjust the third-party domains to match your stack.
  3. Deploy in report-only mode first. Send the header as Content-Security-Policy-Report-Only (note the suffix). The browser logs violations to the console but doesn't block anything. Use your site normally for a week and watch the console for Refused to load messages. Each one names a domain your policy missed.
  4. Tighten the policy until clean. Add the missing domains to the relevant directive. Better still, refactor the site to use fewer external services. Every https:// allowance in your CSP is a tradeoff.
  5. Switch to enforcing mode. Rename the header from Content-Security-Policy-Report-Only to Content-Security-Policy. Now the browser enforces it.

Owner: Your developer or web host. · Time: 1-2 hours of audit + 1 week of observe-mode + 30 minutes to flip on.

Common gotchas

How to verify the fix

Run a Vantyris scan. It checks that a CSP is present and flags the common weaknesses ('unsafe-inline', 'unsafe-eval', a missing default-src). For a detailed CSP grade, run your site through observatory.mozilla.org.

Cyber Essentials alignment

This finding informs the following Cyber Essentials control areas (the UK government's baseline scheme, a sound checklist in any country):

Vantyris is not a CE certifying body. The mapping above is informational.

Common follow-up questions

Do I need CSP if I have HTTPS?

Yes. HTTPS encrypts the connection. CSP controls what code runs on the page. Different protections, different threats.

Will CSP break my analytics?

Only if your analytics runs on a domain you didn't allow. Add the analytics domain to script-src and connect-src and it works fine.

What's the difference between CSP and Permissions-Policy?

CSP controls what code runs. Permissions-Policy controls which browser features the page can use (camera, microphone, geolocation, etc.). Different headers that complement each other.

References

Related explainers

Want Vantyris to check your domain for this and 196 other problems?

The teaser scan is free and needs no card. A verified scan starts at $10€10£10A$15¥1,500AED 40 and comes with the workspace: finding workflow, score trend, three PDF layouts, share links and monitoring.

Written by Vantyris