Check your site

Which countries’ laws

We check against the laws of all five markets. You can pick several at once, say the EU and the US if you ship between them or sell to customers in both.

Security

Content-Security-Policy: how to roll out CSP without breaking anything

CSP stops foreign scripts running on your site. Report-only mode, a staged rollout, nonces and common mistakes. A ready starter policy included.

Checked against sources: 11 October 2026

  • 2modes: report-only and enforcing
  • 3rollout steps without breakage
  • 0unsafe-inline in script-src for a strict policy

What CSP does

The policy lists the sources a page may load scripts, styles, images and requests from. If an attacker injects a script into a comment or hacks a library you include, the browser refuses to run it.

Roll it out in three steps

  • Enable the Content-Security-Policy-Report-Only header: it blocks nothing and only logs in the console what it would block.
  • Browse the main pages, collect the violations and add the hosts you need: analytics, widgets, the payment gateway.
  • When the console is quiet rename the header to Content-Security-Policy and watch for errors for a week.
Content-Security-Policy-Report-Only: default-src 'self'; script-src 'self' https://www.googletagmanager.com; img-src 'self' data: https:; object-src 'none'; base-uri 'self'; frame-ancestors 'self'

What to avoid

unsafe-inline and unsafe-eval in script-src cancel the protection: injected code runs through exactly those. If you cannot live without inline scripts use a one-time nonce the server adds to every response. A '*' source and the data: or https: schemes in script-src allow scripts from anywhere. The headers generator builds a starter policy.

Frequently asked

Why does CSP break analytics?

Analytics and widgets load scripts from other domains. They must be listed in script-src and connect-src. Report-only mode shows exactly which hosts are missing.

Does CSP replace X-Frame-Options?

Partly: the frame-ancestors directive does the same, stronger. The old header stays for compatibility with old browsers.

Does CSP affect SEO?

Not directly. But a protected site is hacked less often, and a hacked site loses rankings and lands on warning lists.

Sources

Check your site

Awe Check shows in a minute which of this is broken on your site and calculates the possible fine.

Check a site
Awe Check Pro

Watch your site and competitors

Pro checks the site on its own, compares it with competitors and tells you when the score drops or SSL and the domain are about to expire.

  • Watch your own sites and competitors
  • Site battles: where you lag and where you lead
  • Domain and SSL expiry in advance
  • Telegram and email alerts
Payment is not connected yet. Press it and we will tell you first when it launches. Nothing is charged.
Compare with a competitorWhat Pro includes →