Content-Security-Policy-Report-Only

HTTP response header

The HTTP Content-Security-Policy-Report-Only response header allows web developers to experiment with policies by monitoring (but not enforcing) their effects. These violation reports consist of JSON documents sent via an HTTP POST request to the specified URI

Header usage statistics

Content-Security-Policy-Report-Only response header information and usage statistics.
Websites using header Content-Security-Policy-Report-Only297,628
Percentage of websites that use Content-Security-Policy-Report-Only header0.48%
Total discovered header valuesMore than 10,000
Header uses directivesYes
Header values are unique or randomNo
Most popular in the country United States

Content-Security-Policy-Report-Only directives (29 total)

  • base-uri
  • block-all-mixed-content
  • child-src
  • connect-src
  • default-src
  • font-src
  • form-action
  • frame-ancestors
  • frame-src
  • img-src
  • manifest-src
  • media-src
  • navigate-to
  • object-src
  • plugin-types
  • prefetch-src
  • report-to
  • report-uri
  • require-trusted-types-for
  • sandbox
  • script-src
  • script-src-attr
  • script-src-elem
  • style-src
  • style-src-attr
  • style-src-elem
  • trusted-types
  • upgrade-insecure-requests
  • worker-src

Content-Security-Policy-Report-Only Directives

Content-Security-Policy-Report-Only directives value information and usage statistics
DirectiveShareWebsites countUnique Values
upgrade-insecure-requests3.80%11,30618
block-all-mixed-content3.46%10,3029
report-uri<0.1%752
worker-src<0.1%721
child-src<0.1%592
frame-ancestors<0.1%572
base-uri<0.1%492
media-src<0.1%411
object-src<0.1%261
report-to<0.1%192
sandbox<0.1%152
connect-src<0.1%141
default-src<0.1%141
form-action<0.1%121
frame-src<0.1%121
manifest-src<0.1%91
prefetch-src<0.1%91
trusted-types<0.1%91
font-src<0.1%81
img-src<0.1%71
script-src<0.1%71
script-src-attr<0.1%71
style-src<0.1%71
script-src-elem<0.1%61
style-src-attr<0.1%61
style-src-elem<0.1%61
require-trusted-types-for<0.1%51
navigate-to<0.1%41
plugin-types<0.1%41

Connected technologies

Technologies that utilize the header
Amazon S3, category Content Delivery Networks, total 1,114,185 websites
Recurly, category Payment Processors, total 15,741 websites
Kameleoon, category Personalization, total 3,987 websites
Payplug, category Payment Processors, total 3,113 websites
Cardinal, category Payment Processors, total 1,050 websites
Medallia, category User Onboarding, total 791 websites
Zuora, category Payment, total 560 websites
Digital River, category Ecommerce, total 113 websites
RapidSec, category Security Solutions, total 85 websites

Websites utilizing Content-Security-Policy-Report-Only

List of websites that use Content-Security-Policy-Report-Only header
DomainCountryRankContacts
google.com United States3
googletagmanager.com United States8
maps.google.com United States24
accounts.google.com United States28
google-analytics.com United States38
support.google.com United States43
See full domain list

Common header values

List of top common Content-Security-Policy-Report-Only header values
Header valueValue prevalence
default-src *;script-src 'unsafe-inline' 'unsafe-eval' *;style-src 'unsafe-inline' *;connect-src * blob:;report-uri https://cdn.website-start.de/app/reporting/policyviolation/submit30.80%
default-src *;script-src 'unsafe-inline' 'unsafe-eval' *;style-src 'unsafe-inline' *;connect-src * blob:;report-uri https://cdn.initial-website.com/app/reporting/policyviolation/submit4.64%
default-src https: blob: data: 'unsafe-inline' 'unsafe-eval'; report-to blogspot; report-uri https://www.blogger.com/cspreport3.37%
upgrade-insecure-requests; default-src 'self' https: data: wss: 'unsafe-inline' 'unsafe-eval';2.09%
default-src http: https: 'self'; connect-src 'self' http: https: javascript: wss: *.doubleclick.net *.facebook.com *.freshdesk.com ajax.googleapis.com *.google-analytics.com www.justuno.com *.loyaltylion.net www.shopboostapp.com *.smartsupp.com *.tawk.to 2.00%
block-all-mixed-content; report-uri https://blog.hatena.ne.jp/api/csp_report1.54%
frame-ancestors 'self'1.51%
default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; report-uri /csp-report1.32%
frame-ancestors 'self' *.qualtrics.com *.my.salesforce.com *.visualforce.com *.visual.force.com *.lightning.force.com; report-uri https://sjc1.qualtrics.com/csp-report0.91%
default-src *;script-src 'unsafe-inline' 'unsafe-eval' *;style-src 'unsafe-inline' *;connect-src * blob:;report-uri https://cdn.eu.mywebsite-editor.com/app/reporting/policyviolation/submit0.75%
require-trusted-types-for 'script';report-uri https://csp.withgoogle.com/csp/6b8ce7c01e3dacd3d2c7a8cd322ff979/mr0.57%
default-src https: wss: 'unsafe-inline' 'unsafe-eval' data:; report-uri https://sp.report-uri.com/r/default/csp/reportOnly0.55%
script-src 'unsafe-eval' blob: 'self' https: 'self' data: 'unsafe-inline' 'unsafe-eval' blob: 'unsafe-inline' internal-soap.wikia.com internal-soap.fandom.com internal-soap.wikia.org internal-soap.gamepedia.com www.fandom.com www.wikia.com www.wikia.org w0.50%
report-uri /csp-violation-report-endpoint0.48%
default-src * 'unsafe-eval' 'unsafe-inline' 'unsafe-dynamic' data: filesystem: about: blob: ws: wss:0.44%
default-src * data: ; script-src * 'unsafe-inline' 'unsafe-eval' ; style-src * 'unsafe-inline' data: ; frame-ancestors 'none'; report-uri /csp-violation-report-endpoint/0.44%
default-src 'self' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' data: blob: ; form-action 'none' ; frame-ancestors 'self' ; script-src 'unsafe-eval' 'unsafe-hashes' 'report-sample'; report-uri /csp_report0.42%
script-src 'unsafe-eval' blob: 'self' meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org 0.35%
default-src https: data: blob: wss: 'unsafe-inline' 'unsafe-eval'; report-uri /_csp0.33%
default-src acsbap.com *.acsbapp.com *.google-analytics.com *.voicepad.com analytics.crea.ca *.hireaiva.com aiva-live-chat.storage.googleapis.com;frame-src 'self' 'unsafe-inline' *.google.com *.google-analytics.com *.googletagmanager.com *.onboardnavigato0.32%