Content Security Policy (CSP)
An HTTP security header that helps prevent XSS and data injection attacks by specifying which content sources a browser should trust.
Content Security Policy is a browser security mechanism delivered via HTTP headers that restricts which resources (scripts, styles, images, fonts) a page can load. By defining a whitelist of trusted content sources, CSP prevents the execution of injected malicious scripts.
A well-configured CSP significantly reduces the risk of XSS attacks: even if an attacker injects a script tag, the browser will refuse to execute it if the source isn’t in the policy. CSP can also block inline scripts, eval(), and data: URIs.
For teams building web applications, implementing CSP is a critical defense layer. Combined with secure credential management and input validation, CSP helps create a robust security posture against client-side attacks.
Stop sharing passwords in spreadsheets
TeamPassword stores, shares and rotates your team credentials, encrypted end to end.
Trusted by 900+ agencies and small teams worldwide