Scan rule · RSC-SEC-101
Security policy allows scripts directly in the HTML
Checks whether the Content Security Policy allows 'unsafe-inline' in script-src (or default-src) without a nonce or hash.
Why this matters
A Content Security Policy decides which code may run in the browser. With 'unsafe-inline', any code written directly into the HTML may run as well — and that is exactly where injected code lands in most attacks via forms, comments or listing texts.
We only report this when the policy otherwise works: it names allowed sources, and nonce, hash and 'strict-dynamic' are missing — with those, browsers ignore 'unsafe-inline' anyway. A policy that limits nothing is already listed under “Content Security Policy without effect”.
Scan tier
How to fix it
Move inline scripts into files or give them a nonce or hash, and remove 'unsafe-inline' from script-src. Many frameworks (Next.js, Astro, SvelteKit) can generate nonces or hashes themselves.