Content-Security-Policy-Report-Only

HTTP response header

The HTTP Content-Security-Policy-Report-Only response header allows web developers to experiment with policies by monitoring (but not enforcing) their effects. These violation reports consist of JSON documents sent via an HTTP POST request to the specified URI

Header usage statistics

Content-Security-Policy-Report-Only response header information and usage statistics.

Websites using header Content-Security-Policy-Report-Only 86,121
Percentage of websites that use Content-Security-Policy-Report-Only header 0.75%
Total discovered header values 3,875
Header uses directives Yes
Header values are unique or random No
Most popular in the country United States of America

Content-Security-Policy-Report-Only Directives (15 total)

  • block-all-mixed-content
  • upgrade-insecure-requests
  • media-src
  • sandbox
  • object-src
  • report-uri
  • child-src
  • form-action
  • prefetch-src
  • trusted-types
  • default-src
  • base-uri
  • plugin-types
  • font-src
  • frame-ancestors

Content-Security-Policy-Report-Only Directives

Content-Security-Policy-Report-Only directives value information and usage statistics

Directive Share Websites count Unique Values
block-all-mixed-content 48.86% 42,081 9
upgrade-insecure-requests 0.25% 217 12
frame-ancestors <0.1% 14 1
report-uri <0.1% 3 1
base-uri <0.1% 3 1
media-src <0.1% 2 1
default-src <0.1% 2 1
plugin-types <0.1% 2 1
sandbox <0.1% 1 1
object-src <0.1% 1 1
child-src <0.1% 1 1

Distribution by websites popularity

Content-Security-Policy-Report-Only detection in the top websites by popularity

Top 10k sites 202 websites
Top 100k sites 582 websites
Top 1m sites 3,276 websites

Websites utilizing Content-Security-Policy-Report-Only

List of websites that use Content-Security-Policy-Report-Only header

Domain Country Rank Contacts
www.pinterest.com United States of America 13
play.google.com United States of America 19
support.google.com United States of America 20
vimeo.com United States of America 26
www.telegraph.co.uk United States of America 64
www.linkedin.com United States of America 30,270
See full domain list

Geographical Distribution

Header usage distribution by websites across the globe.






Common header values

List of top common Content-Security-Policy-Report-Only header values

Header value Value prevalence
block-all-mixed-content; report-uri https://blog.hatena.ne.jp/api/csp_report 59.83%
default-src https: ''self'' data: blob:; script-src https: ''self'' data: ''unsafe-inline'' ''unsafe-eval'' blob:; style-src https: ''self'' ''unsafe-inline'' blob:; report-uri https://services.wikia.com/csp-logger/csp/app 6.74%
default-src * ''unsafe-eval'' ''unsafe-inline'' data:;report-uri //pointman.alibaba.com/csp?app=ae_default 5.35%
default-src *;script-src ''unsafe-inline'' ''unsafe-eval'' *;style-src ''unsafe-inline'' *;connect-src * blob:;report-uri https://cdn.website-start.de/app/reporting/policyviolation/submit 4.35%
default-src https: ''self'' data: blob:; script-src https: ''self'' data: ''unsafe-inline'' ''unsafe-eval'' blob:; style-src https: ''self'' ''unsafe-inline'' blob:; report-uri https://services.fandom.com/csp-logger/csp/app 2.16%
default-src *;script-src ''unsafe-inline'' ''unsafe-eval'' *;style-src ''unsafe-inline'' *;connect-src * blob:;report-uri https://cdn.initial-website.com/app/reporting/policyviolation/submit 1.24%
default-src https: blob: data: ''unsafe-inline'' ''unsafe-eval''; report-uri https://www.blogger.com/cspreport 1.10%
default-src https:; script-src https: ''unsafe-eval'' ''unsafe-inline''; style-src https: ''unsafe-inline''; img-src https: data:; font-src https: data:; report-uri /csp-report 1.08%
default-src https: wss: data: blob: ''unsafe-inline'' ''unsafe-eval''; report-uri https://studio.digital.vistaprint.com/csp/report/published 1.07%
script-src ''unsafe-eval'' blob: ''self'' meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikivoyage.org *.mediawiki.org 1.03%
frame-ancestors ''self'' *.qualtrics.com; report-uri https://sjc1.qualtrics.com/csp-report 0.95%
default-src https: data: ; script-src ''self'' ''unsafe-inline'' ''unsafe-eval'' https://*.facebook.com https://*.google.com https://*.googleapis.com https://*.googletagmanager.com https://*.gstatic.com https://*.kampyle.com https://*.paypal.com https://* 0.85%
font-src ''self'' ''unsafe-inline''; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test. 0.69%
default-src https: blob: ''unsafe-inline'' ''unsafe-eval''; img-src https: data:; font-src ''self'' data: https: ''unsafe-inline''; connect-src https: wss: ''unsafe-inline''; report-uri https://hi.report-uri.io/r/default/csp/reportOnly 0.64%
default-src data: https: ''unsafe-inline'' ''unsafe-eval''; report-uri https://a3frkpbrnzxvdwnkpssx604n.httpschecker.net/report; report-to https://a3frkpbrnzxvdwnkpssx604n.httpschecker.net/report 0.47%
script-src ''unsafe-eval'' ''self'' https: ''self'' data: ''unsafe-inline'' ''unsafe-eval'' blob: ''unsafe-inline'' internal-soap.wikia.com internal-soap.fandom.com internal-soap.wikia.org internal-soap.gamepedia.com www.fandom.com www.wikia.com www.wikia 0.45%
default-src https: wss: ''unsafe-inline'' ''unsafe-eval'' data:; report-uri https://sp.report-uri.com/r/default/csp/reportOnly 0.36%
default-src https: wss: data: blob: ''unsafe-inline'' ''unsafe-eval''; report-uri https://logger.kataweb.it/csp/ 0.35%
default-src https: blob: ''unsafe-inline'' ''unsafe-eval''; img-src https: data:; report-uri https://firmsites.report-uri.com/r/t/csp/reportOnly 0.33%
font-src ''self'' ''unsafe-inline''; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardina 0.25%