Barrion Docs
Passive Scanning

Content Security Policy (CSP)

What Barrion checks when it evaluates your site's Content Security Policy.

Barrion checks whether your site has a Content Security Policy, a browser instruction that controls which scripts, styles, and resources are allowed to load. A missing or weak CSP makes your site more vulnerable to attacks where malicious code is injected into your pages.

What Barrion Checks

CSP Header Presence

Barrion checks whether the Content-Security-Policy response header exists. Without it, the browser has no restrictions on what can load on your page.

Severity: High

CSP Bypass Patterns

Barrion analyzes your CSP for configurations that weaken or effectively disable its protection, such as allowing all inline scripts or permitting any external source. A CSP with these patterns offers little real protection.

Severity: Medium

CSP Console Errors

Using a headless browser, Barrion counts how many CSP violations occur when loading your page. Violations can indicate that your policy is blocking legitimate content, or that third-party scripts are attempting to load unauthorized resources.

Severity: Medium

Trusted Types

Barrion checks whether your CSP includes Trusted Types, an advanced browser feature that prevents a specific class of script injection attacks at the code level.

Severity: Medium

What to Do

CSP configuration is a developer task. Share your Barrion findings with your development team. The findings include details about which specific patterns were detected to help prioritize fixes. If you do not have a CSP at all, starting with one, even a basic policy, provides meaningful protection.