Skip to content

Scan rule · RSC-SEC-101

Security policy allows scripts directly in the HTML

SecuritySeverity: LowCWE-79OWASP A03-2021

Checks whether the Content Security Policy allows 'unsafe-inline' in script-src (or default-src) without a nonce or hash.

Why this matters

A Content Security Policy decides which code may run in the browser. With 'unsafe-inline', any code written directly into the HTML may run as well — and that is exactly where injected code lands in most attacks via forms, comments or listing texts.

We only report this when the policy otherwise works: it names allowed sources, and nonce, hash and 'strict-dynamic' are missing — with those, browsers ignore 'unsafe-inline' anyway. A policy that limits nothing is already listed under “Content Security Policy without effect”.

Scan tier

External scan (anonymous)

How to fix it

Move inline scripts into files or give them a nonce or hash, and remove 'unsafe-inline' from script-src. Many frameworks (Next.js, Astro, SvelteKit) can generate nonces or hashes themselves.

Scan your own app for free