Subresource Integrity: protect your site from a compromised CDN
The integrity attribute makes the browser reject a CDN script or style if the file was tampered with. How to generate the hash and when SRI is not needed.
Checked against sources: 11 October 2026

- sha384a typical SRI hash algorithm
- 1attribute, integrity, blocks a swapped file
- 7public CDNs Awe Check inspects
The risk
The site loads jQuery, Bootstrap or Tailwind from a public CDN. If the CDN is compromised or a library author ships a malicious release, foreign code runs for all your visitors: it can steal form data and swap payment pages.
How to enable it
Add an integrity attribute with the hash of the reference file, plus crossorigin, to the tag. The browser compares the file with the hash and refuses to run it if it differs.
<script src="https://cdn.jsdelivr.net/npm/lib@1.2.3/dist/lib.min.js" integrity="sha384-…" crossorigin="anonymous"></script>
Getting the hash and when SRI is not needed
- Compute it with openssl dgst -sha384 -binary file | openssl base64 -A, or copy it from the CDN page.
- Pin the library version in the URL: a “latest” file changes and the hash stops matching.
- For scripts the vendor updates itself (Google Tag Manager, Yandex Metrica) SRI is not used and CSP covers the risk.
- Simplest of all: host libraries yourself, so tampering requires breaking into your own server.
Frequently asked
What if the hash does not match?
The browser blocks the file and the page may break. That is why SRI goes with a pinned library version and a test on a staging copy.
How does SRI differ from CSP?
CSP decides where code may load from. SRI checks that the file from an allowed address was not swapped. Together they give defence in depth.
Which CDNs does Awe Check inspect?
Popular library hosts: jsDelivr, cdnjs, unpkg, the jQuery CDN, Bootstrap CDN, Google Hosted Libraries and the Tailwind CDN. Services like Google Tag Manager are not counted.
