Injection & XSS
Content-Security-Policy
The strongest defence against cross-site scripting.
What it is
CSP tells the browser which sources of script, style, images, frames and other content are allowed to load and execute. Anything not on the allowlist is blocked.
Why it matters
Even if an attacker injects markup into your page, a good CSP stops their script from running — turning many XSS bugs from critical into harmless.
Risk without it
Without CSP, any injected or third-party script runs with full access to the DOM, cookies (that aren't HttpOnly) and user actions. A single XSS becomes account takeover.
Recommended
default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'none'; frame-ancestors 'none'. Prefer per-request nonces + 'strict-dynamic'; avoid 'unsafe-inline' and 'unsafe-eval'.
Set it
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'none'; frame-ancestors 'none'" always;