Skip to main content

Supply chain

Subresource Integrity: the third-party script defence most sites skip.

Published 2026-05-11 · Last updated 2026-05-11 · Vantyris editorial

Most small business sites load five to twenty scripts from third-party CDNs (analytics, fonts, A/B testing, chat widgets, payment SDKs). Each one is a supply-chain risk. If the CDN is compromised, your site runs whatever malicious code the attacker swaps in, in your visitors' browsers, under your domain. Subresource Integrity (SRI) is a one-line defence, enforced by the browser, that closes this gap. It takes minutes to add and stops 100% of the attack class.

What this means for your business

How to fix

Add an integrity attribute with an SHA-384 hash and crossorigin="anonymous" to every external script and stylesheet tag. Use the CDN's published hash, or compute one with openssl.

  1. List your external scripts. Open Chrome DevTools → Network and reload. Filter by JS + CSS and note every domain that isn't yours. Common ones: cdnjs.cloudflare.com, jsdelivr.net, unpkg.com, fonts.googleapis.com, google-analytics.com, googletagmanager.com.
  2. Decide which scripts you control the version of. SRI only works if the file at the URL never changes. That holds for pinned-version URLs (cdn.example.com/library@1.2.3/dist.js). It does NOT hold for unpinned URLs (cdn.example.com/library/latest/dist.js), or for dynamic scripts like Google Analytics (gtag.js), which Google updates regularly. Skip those.
  3. Generate or copy the SRI hash for each pinned script. Most CDNs publish SRI hashes on their official pages (cdnjs.cloudflare.com shows them next to the URL). Or compute one locally with curl -sL <url> | openssl dgst -sha384 -binary | openssl base64 -A, then prefix the result with sha384-.
  4. Update each script and stylesheet tag. Add the attributes: <script src="https://cdnjs.cloudflare.com/library@1.2.3/dist.js" integrity="sha384-<hash>" crossorigin="anonymous"></script>. The crossorigin attribute is required for SRI to work cross-origin.
  5. Test in a staging environment first. If the hash is wrong, the browser refuses to load the script, and your site breaks silently for visitors. Check in DevTools that no script is blocked before shipping to production.

Owner: Your developer. · Time: 15-30 minutes for a typical site with 5-10 external scripts.

Common gotchas

How to verify the fix

Run a Vantyris scan. The Supply chain category lists every external script and flags the ones without SRI. Mozilla Observatory (observatory.mozilla.org) has its own SRI check too.

Cyber Essentials alignment

This finding informs the following Cyber Essentials control areas (the UK government's baseline scheme, a sound checklist in any country):

Vantyris is not a CE certifying body. The mapping above is informational.

Common follow-up questions

Is SRI worth the effort for a small site?

Yes. It's one attribute per script tag and a few minutes of work, and it protects against an entire attack class. Next to most security work, it's worth doing first.

Should I host third-party scripts on my own server instead?

Sometimes. Self-hosting removes the CDN supply-chain risk entirely. The tradeoff is the caching benefit: visitors who already loaded the script from the CDN on another site don't get it from cache on yours. For low-traffic sites, self-host. For traffic-sensitive sites, use SRI with the CDN.

What if the third party updates their script and breaks my site?

That's the cost-benefit of SRI. With SRI, you choose when to upgrade. Without it, the CDN can change the file under you at any time. Most sites prefer the explicit upgrade.

References

Related explainers

Want Vantyris to check your domain for this and 196 other problems?

The teaser scan is free and needs no card. A verified scan starts at $10€10£10A$15¥1,500AED 40 and comes with the workspace: finding workflow, score trend, three PDF layouts, share links and monitoring.

Written by Vantyris