Glossary · HTTP, edge and rendering
Content-Security-Policy
A response header that tells a browser which sources a page may load scripts, styles, images, frames and connections from.
What Content-Security-Policy means
A response header that tells a browser which sources a page may load scripts, styles, images, frames and connections from. It is the one security header that can break a page at HTTP 200, which is why it has a report-only mode; a policy that permits 'unsafe-inline' for scripts removes most of the protection it was written for.
What Content-Security-Policy can and cannot support
| It can support | It cannot support |
|---|---|
| A response header that tells a browser which sources a page may load scripts, styles, images, frames and connections from. | It is the one security header that can break a page at HTTP 200, which is why it has a report-only mode; a policy that permits 'unsafe-inline' for scripts removes most of the protection it was written for. |
How CrawlCheck measures Content-Security-Policy
One finding code in the scanner read this. The share of all scans carrying each is computed from the live corpus when this page is served, not typed into it.
| Finding code | Share of scans | Guide |
|---|---|---|
CSP_REPORTING_BROKEN | 0.3% | CSP rollout: from report-only to enforced without a break |
Every code, its rule and its current rate: the dataset page. Scan a site to see which apply to it.
Where Content-Security-Policy comes up on this site
- CSP rollout: from report-only to enforced without a breakA Content-Security-Policy is the only response header that can break a page while returning 200.
- Our security headers skipped every signed-in sessionOn 24 September crawlcheck.io shipped two security changes in one afternoon: a Content-Security-Policy in report-only mode with a per-response nonce, and a tightening of the CORS headers so that credentialed cross-origin requests were answered only where…
Definitions that name Content-Security-Policy
Related terms in HTTP, edge and rendering
The delivery layer between an origin and a client: proxies, caches, redirects, status codes and the headers that decide what a crawler actually received.
Origin server · Reverse proxy · CDN · Edge node · WAF · Bot score · TLS handshake · DNS resolution · DNS timeout · Connection timeout · Read timeout · Redirect chain · Redirect loop · 301 redirect · 302 redirect · 307 redirect · 308 redirect · 304 response · 404 response · 410 response · 429 response · 500 response · 502 response · 503 response · 504 response · HEAD request · GET request · Content type · MIME sniffing · Content encoding · Compression · Brotli · ETag · Last-Modified · If-None-Match · Cache hit · Cache miss · Cache key · Vary header · Stale response · Stale-while-revalidate · Edge redirect · Origin bypass · Response parity · Header parity · hreflang · canonical URL · HSTS · HSTS preload list · CSP nonce · edge cache · cache split · cache-buster · Cache-Control · Age header · render-blocking resource · payload text share · lazy loading · 404 and 410 status codes
Questions about Content-Security-Policy
What is Content-Security-Policy?
A response header that tells a browser which sources a page may load scripts, styles, images, frames and connections from.
What does Content-Security-Policy not show or guarantee?
It is the one security header that can break a page at HTTP 200, which is why it has a report-only mode; a policy that permits 'unsafe-inline' for scripts removes most of the protection it was written for.
How does CrawlCheck measure Content-Security-Policy?
Through the finding code CSP_REPORTING_BROKEN, each with a stated rule, evidence bytes and a live share of scans on the dataset page.
Which area of the glossary does Content-Security-Policy belong to?
HTTP, edge and rendering: The delivery layer between an origin and a client: proxies, caches, redirects, status codes and the headers that decide what a crawler actually received.
← HSTS preload list · CSP nonce →
See it in the full glossary · 668 terms across 19 areas.