Content-Security-Policy-Report-Only

HTTP response header

The HTTP Content-Security-Policy-Report-Only response header allows web developers to experiment with policies by monitoring (but not enforcing) their effects. These violation reports consist of JSON documents sent via an HTTP POST request to the specified URI

Header usage statistics

Content-Security-Policy-Report-Only response header information and usage statistics.

Websites using header Content-Security-Policy-Report-Only 79,708
Percentage of websites that use Content-Security-Policy-Report-Only header 0.73%
Total discovered header values 5,006
Header uses directives Yes
Header values are unique or random No
Most popular in the country United States of America

Content-Security-Policy-Report-Only Directives (25 total)

  • base-uri
  • block-all-mixed-content
  • child-src
  • connect-src
  • default-src
  • font-src
  • form-action
  • frame-ancestors
  • frame-src
  • img-src
  • manifest-src
  • media-src
  • object-src
  • plugin-types
  • prefetch-src
  • report-to
  • report-uri
  • sandbox
  • script-src
  • script-src-attr
  • script-src-elem
  • style-src-attr
  • style-src-elem
  • upgrade-insecure-requests
  • worker-src

Content-Security-Policy-Report-Only Directives

Content-Security-Policy-Report-Only directives value information and usage statistics

Directive Share Websites count Unique Values
block-all-mixed-content 54.90% 43,759 11
upgrade-insecure-requests 0.35% 276 11
child-src <0.1% 7 3
frame-ancestors <0.1% 7 2
object-src <0.1% 7 3
media-src <0.1% 5 3
base-uri <0.1% 4 3
default-src <0.1% 4 1
frame-src <0.1% 4 1
report-uri <0.1% 4 1
form-action <0.1% 3 2
plugin-types <0.1% 3 1
prefetch-src <0.1% 3 3
font-src <0.1% 2 1
img-src <0.1% 2 1
sandbox <0.1% 2 1
worker-src <0.1% 2 1
connect-src <0.1% 1 1
manifest-src <0.1% 1 1
report-to <0.1% 1 1
script-src <0.1% 1 1
script-src-attr <0.1% 1 1
script-src-elem <0.1% 1 1
style-src-attr <0.1% 1 1
style-src-elem <0.1% 1 1

Distribution by websites popularity

Content-Security-Policy-Report-Only detection in the top websites by popularity

Top 10k sites 238 websites
Top 100k sites 716 websites
Top 1m sites 3,922 websites

Websites utilizing Content-Security-Policy-Report-Only

List of websites that use Content-Security-Policy-Report-Only header

Domain Country Rank Contacts
www.linkedin.com United States of America 9
www.pinterest.com United States of America 13
play.google.com United States of America 19
support.google.com United States of America 20
vimeo.com United States of America 26
developers.google.com United States of America 28
See full domain list
Flat price per report, subscription is not required.

Geographical Distribution

Header usage distribution by websites across the globe.






Common header values

List of top common Content-Security-Policy-Report-Only header values

Header value Value prevalence
block-all-mixed-content; report-uri https://blog.hatena.ne.jp/api/csp_report 64.31%
script-src 'unsafe-eval' 'self' https: 'self' data: 'unsafe-inline' 'unsafe-eval' blob: 'unsafe-inline' internal-soap.wikia.com internal-soap.fandom.com internal-soap.wikia.org internal-soap.gamepedia.com www.fandom.com www.wikia.com www.wikia.org www.gam 4.66%
default-src *;script-src 'unsafe-inline' 'unsafe-eval' *;style-src 'unsafe-inline' *;connect-src * blob:;report-uri https://cdn.website-start.de/app/reporting/policyviolation/submit 4.46%
default-src https: blob: data: 'unsafe-inline' 'unsafe-eval'; report-uri https://www.blogger.com/cspreport 1.77%
default-src *;script-src 'unsafe-inline' 'unsafe-eval' *;style-src 'unsafe-inline' *;connect-src * blob:;report-uri https://cdn.initial-website.com/app/reporting/policyviolation/submit 1.28%
script-src 'unsafe-eval' blob: 'self' meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikivoyage.org *.mediawiki.org 'uns 1.14%
default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; report-uri /csp-report 1.04%
frame-ancestors 'self' *.qualtrics.com *.my.salesforce.com *.visualforce.com *.lightning.force.com; report-uri https://sjc1.qualtrics.com/csp-report 1.03%
frame-ancestors 'self'; report-uri https://stores.jp/content_security_policy_reports 0.78%
font-src 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.auth 0.72%
default-src https: blob: 'unsafe-inline' 'unsafe-eval'; img-src https: data:; font-src 'self' data: https: 'unsafe-inline'; connect-src https: wss: 'unsafe-inline'; report-uri https://hi.report-uri.io/r/default/csp/reportOnly 0.70%
block-all-mixed-content; report-uri /csprep/log 0.61%
default-src data: https: 'unsafe-inline' 'unsafe-eval'; report-uri https://a3frkpbrnzxvdwnkpssx604n.httpschecker.net/report; report-to https://a3frkpbrnzxvdwnkpssx604n.httpschecker.net/report 0.53%
block-all-mixed-content; report-uri /global-cgi-bin/csp-report 0.40%
default-src https: wss: 'unsafe-inline' 'unsafe-eval' data:; report-uri https://sp.report-uri.com/r/default/csp/reportOnly 0.39%
default-src https: wss: data: blob: 'unsafe-inline' 'unsafe-eval'; report-uri https://logger.kataweb.it/csp/ 0.38%
font-src 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcom 0.37%
child-src mc.yandex.md mc.yandex.ru;connect-src mc.admetrica.ru mc.yandex.ru yandex.ru;default-src 'none';img-src 'self' *.verify.yandex.ru avatars.mds.yandex.net awaps.yandex.net data: favicon.yandex.net mc.admetrica.ru mc.yandex.com mc.yandex.ru yandex. 0.35%
frame-ancestors 'self' *.hudl.com *.youtube.com *.sendtonews.com *.cbssports.com *.247sports.com *.scout.com *.ampproject.org *.amp.cloudflare.com; default-src https: 'unsafe-inline' 'unsafe-eval' wss: ;img-src https: data: blob: ; font-src https: data:; 0.24%
default-src https: data: 'unsafe-inline' 'unsafe-eval' 0.24%