Content-Security-Policy: how to roll out CSP without breaking anything
CSP stops foreign scripts running on your site. Report-only mode, a staged rollout, nonces and common mistakes. A ready starter policy included.
Checked against sources: 11 October 2026

- 2modes: report-only and enforcing
- 3rollout steps without breakage
- 0unsafe-inline in script-src for a strict policy
What CSP does
The policy lists the sources a page may load scripts, styles, images and requests from. If an attacker injects a script into a comment or hacks a library you include, the browser refuses to run it.
Roll it out in three steps
- Enable the Content-Security-Policy-Report-Only header: it blocks nothing and only logs in the console what it would block.
- Browse the main pages, collect the violations and add the hosts you need: analytics, widgets, the payment gateway.
- When the console is quiet rename the header to Content-Security-Policy and watch for errors for a week.
Content-Security-Policy-Report-Only: default-src 'self'; script-src 'self' https://www.googletagmanager.com; img-src 'self' data: https:; object-src 'none'; base-uri 'self'; frame-ancestors 'self'
What to avoid
unsafe-inline and unsafe-eval in script-src cancel the protection: injected code runs through exactly those. If you cannot live without inline scripts use a one-time nonce the server adds to every response. A '*' source and the data: or https: schemes in script-src allow scripts from anywhere. The headers generator builds a starter policy.
Frequently asked
Why does CSP break analytics?
Analytics and widgets load scripts from other domains. They must be listed in script-src and connect-src. Report-only mode shows exactly which hosts are missing.
Does CSP replace X-Frame-Options?
Partly: the frame-ancestors directive does the same, stronger. The old header stays for compatibility with old browsers.
Does CSP affect SEO?
Not directly. But a protected site is hacked less often, and a hacked site loses rankings and lands on warning lists.
