headers by 0x6a03448f4d
← All headers
Injection & XSS

Content-Security-Policy

The strongest defence against cross-site scripting.

What it is

CSP tells the browser which sources of script, style, images, frames and other content are allowed to load and execute. Anything not on the allowlist is blocked.

Why it matters

Even if an attacker injects markup into your page, a good CSP stops their script from running — turning many XSS bugs from critical into harmless.

Risk without it

Without CSP, any injected or third-party script runs with full access to the DOM, cookies (that aren't HttpOnly) and user actions. A single XSS becomes account takeover.

Recommended

default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'none'; frame-ancestors 'none'. Prefer per-request nonces + 'strict-dynamic'; avoid 'unsafe-inline' and 'unsafe-eval'.

Set it

add_header Content-Security-Policy "default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'none'; frame-ancestors 'none'" always;

References