Missing Content-Security-Policy header
Without a Content-Security-Policy, any script that reaches your page runs with full access to it — including anything injected through a comment field, a URL parameter, or a compromised third-party widget.
Why it matters
Without a Content-Security-Policy, any script that reaches your page runs with full access to it — including anything injected through a comment field, a URL parameter, or a compromised third-party widget. A CSP is what turns a cross-site scripting bug from a full account takeover into a blocked request in the console. It is the single highest-leverage header you can add, and the one most commonly missing from AI-generated apps, because no framework adds it for you.
How ShipReady detects it
Shared tables and rules for the two halves below. Split because this check was a hybrid: nine rules read the headers of a response we already have, which genuinely differ between routes, while missing-https-redirect probes the http:// equivalent of the origin — one fact, and running it per page would issue the same request ten times.
Detection is deterministic. ShipReady reports this only when it observes the condition directly, and prefers to miss a real problem over inventing one. Rule version 1.3.0.
How to fix it
This is the prompt ShipReady puts in your report — written to be pasted straight into Cursor, Claude Code, or whichever assistant built the app.
Add a Content-Security-Policy header to restrict where resources can be loaded from.
Frequently asked questions
- What does "Missing Content-Security-Policy header" mean?
- Without a Content-Security-Policy, any script that reaches your page runs with full access to it — including anything injected through a comment field, a URL parameter, or a compromised third-party widget.
- How serious is it?
- ShipReady rates this high. Fix before launch. A real weakness that an attacker can act on.
- How do I fix it?
- Paste the fix prompt on this page into Cursor, Claude Code or your AI editor. It is the same prompt ShipReady puts in your report.
- Can I check my own site?
- Yes — ShipReady scans up to ten pages of any public site for free and reports this alongside every other check.
Related checks
Does your site have this?
ShipReady checks this and 73 other things across up to ten pages of your site. Free, no signup.
Scan my site