Crawlune

Info · Security

Missing Content-Security-Policy header

Why it matters

A CSP limits the damage of injected scripts (XSS).

How to fix it

Add a Content-Security-Policy appropriate to the site's scripts and assets.

How Crawlune finds it

Crawlune flags Missing Content-Security-Policy header automatically on every crawl and lists the affected URLs under theSecurity tab, where you can filter, inspect each page and export the list to CSV. The free version crawls up to 500 URLs with every check enabled.

Download Crawlune

Related security checks