content-security-policy

HTTP response header

CSP provides a standard method for website owners to declare approved origins of content that browsers should be allowed to load on that website

Header usage statistics

content-security-policy response header information and usage statistics.
Websites using header content-security-policy5,182,073
Percentage of websites that use content-security-policy header6.41%
Total discovered header valuesMore than 10,000
Header uses directivesYes
Header values are unique or randomNo
Most popular in the country United States

content-security-policy directives (28 total)

  • base-uri
  • block-all-mixed-content
  • child-src
  • connect-src
  • default-src
  • font-src
  • form-action
  • frame-ancestors
  • frame-src
  • img-src
  • manifest-src
  • media-src
  • object-src
  • plugin-types
  • prefetch-src
  • referrer
  • report-to
  • report-uri
  • require-sri-for
  • require-trusted-types-for
  • sandbox
  • script-src
  • script-src-attr
  • style-src
  • style-src-attr
  • trusted-types
  • upgrade-insecure-requests
  • worker-src

content-security-policy Directives

content-security-policy directives value information and usage statistics
DirectiveShareWebsites countUnique Values
upgrade-insecure-requests47.95%2,484,636110
block-all-mixed-content16.59%859,70332
frame-ancestors<0.1%1,6665
default-src<0.1%1,5658
report-uri<0.1%7584
sandbox<0.1%5152
object-src<0.1%3184
base-uri<0.1%2672
media-src<0.1%2112
child-src<0.1%1532
frame-src<0.1%1492
script-src<0.1%963
worker-src<0.1%712
form-action<0.1%532
report-to<0.1%412
connect-src<0.1%392
font-src<0.1%362
style-src<0.1%342
manifest-src<0.1%321
img-src<0.1%271
trusted-types<0.1%253
plugin-types<0.1%191
prefetch-src<0.1%171
require-trusted-types-for<0.1%81
require-sri-for<0.1%71
script-src-attr<0.1%61
referrer<0.1%51
style-src-attr<0.1%11

Connected technologies

Technologies that utilize the header
Amazon S3, category Content Delivery Networks, total 1,234,610 websites
AddThis, category Widgets, total 509,653 websites
Afterpay, category Payment Processors, total 38,379 websites
Algolia, category Widgets, total 35,679 websites
Adobe Analytics, category Marketing Analytics, total 14,237 websites
Apple MapKit JS, category Maps, total 9,483 websites
Albacross, category Advertising, total 6,747 websites
Amazon Cognito, category Social login, total 1,056 websites
Aklamio, category Marketing, total 166 websites
Acquia Content Hub, category Miscellaneous, total 3 websites

content-security-policy header usage distribution by website rank



Geographical Distribution

Header usage distribution by websites across the globe.



Websites utilizing content-security-policy

List of websites that use content-security-policy header
DomainCountryRankContacts
www.facebook.com United States2
www.google.com United States3
twitter.com United States7
www.instagram.com United States9
developers.google.com United States11
www.messenger.com United States12
See full domain list

Common header values

List of top common content-security-policy header values
Header valueValue prevalence
upgrade-insecure-requests22.60%
block-all-mixed-content; frame-ancestors 'none'; upgrade-insecure-requests;14.12%
frame-ancestors 'self'12.63%
upgrade-insecure-requests;7.04%
frame-ancestors 'self' godaddy.com *.godaddy.com6.01%
frame-ancestors 'self';1.78%
frame-ancestors 'none';1.49%
frame-ancestors https://*.ionos.com https://*.ionos.at https://*.ionos.co.uk https://*.ionos.de https://*.ionos.es https://*.ionos.fr https://*.ionos.it https://*.ionos.ca https://*.ionos.mx https://*.ionos.us https://*.website-editor.net https://*.mywebs1.16%
block-all-mixed-content0.68%
upgrade-insecure-requests; default-src https: data:; script-src https: data: 'unsafe-inline' 'unsafe-eval'; style-src https: blob: 'unsafe-inline';0.65%
frame-ancestors 'none'0.58%
default-src 'none'; style-src 'unsafe-inline'; img-src data:; connect-src 'self'0.48%
script-src 'self'0.41%
default-src * 'unsafe-inline' 'unsafe-eval' data: blob:;0.39%
frame-ancestors 'self' websitebuilder.godaddy.com websitebuilder.secureserver.net0.38%
default-src 'self' 'unsafe-inline'0.38%
object-src 'none'0.37%
default-src https: data: 'unsafe-inline' 'unsafe-eval'0.32%
default-src 'self'; script-src 'self' 'unsafe-eval' https://challenges.cloudflare.com https://iframe.jimcdn.com https://googleads.g.doubleclick.net https://www.paypal.com https://js.stripe.com https://jimdo-dolphin-static-assets-prod.freetls.fastly.net ht0.31%
frame-ancestors https://manage.menufy.com https://manager.menufy.com0.29%