CSP Builder Guide
A Content-Security-Policy tells the browser which scripts, styles, and frames may load. The builder offers three starting presets. WordPress and Shopify presets still allow unsafe inline script or style because many themes need it. Treat the output as a draft.
Overview
The static preset is the tightest of the three. WordPress and Shopify presets add the hosts those platforms commonly need and warn that unsafe-inline remains. Extra script hosts are appended to script-src. Nothing is sent to your website. After you publish the header on the server or CDN, open the CSP checker with the site URL filled in.
What to check before you publish
- Preset: Use static for a site you control end to end. Use WordPress or Shopify when that is the platform.
- Inline script: A warning means the draft still allows inline script or style.
- Live check: The checker reads the published header. The builder does not.
Preset choice
| Preset | Use when | Tradeoff |
|---|---|---|
| Static | Pages you fully control | Tightest starting point |
| WordPress | WordPress themes and plugins | Allows unsafe-inline |
| Shopify | Shopify storefronts | Allows Shopify CDN and unsafe-inline |
Example draft
Static starting point
default-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; object-src 'none'; upgrade-insecure-requestsRecommended Remediation Flow
- Pick a preset Choose static, WordPress, or Shopify and add extra script hosts only if you know you need them.
- Publish the header Put the draft in your server or CDN configuration. This page does not do that.
- Check the live page Open the CSP checker and confirm the response header matches the draft.
Troubleshooting Common Issues
The site breaks after publishing
The preset blocked a script the theme needs.
- Add that host to extra script hosts and publish again.
- Do not add unsafe-eval unless a plugin requires it.
- Re-run the CSP checker.
Validation Checklist
Post-fix validation
- The live Content-Security-Policy matches the draft you intended.
- You reviewed the unsafe-inline warning.
- The builder did not change the site by itself.
FAQ
Does the builder publish the header?
No.
- You copy the draft.
- You add it on the server or CDN.
- Then you check the live URL.