Browser Hardening 6 min read

CSP Builder Guide

A Content-Security-Policy tells the browser which scripts, styles, and frames may load. The builder offers three starting presets. WordPress and Shopify presets still allow unsafe inline script or style because many themes need it. Treat the output as a draft.

Overview

The static preset is the tightest of the three. WordPress and Shopify presets add the hosts those platforms commonly need and warn that unsafe-inline remains. Extra script hosts are appended to script-src. Nothing is sent to your website. After you publish the header on the server or CDN, open the CSP checker with the site URL filled in.

What to check before you publish

  • Preset: Use static for a site you control end to end. Use WordPress or Shopify when that is the platform.
  • Inline script: A warning means the draft still allows inline script or style.
  • Live check: The checker reads the published header. The builder does not.

Preset choice

PresetUse whenTradeoff
StaticPages you fully controlTightest starting point
WordPressWordPress themes and pluginsAllows unsafe-inline
ShopifyShopify storefrontsAllows Shopify CDN and unsafe-inline

Example draft

Static starting point
default-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; object-src 'none'; upgrade-insecure-requests

Recommended Remediation Flow

  1. Pick a preset Choose static, WordPress, or Shopify and add extra script hosts only if you know you need them.
  2. Publish the header Put the draft in your server or CDN configuration. This page does not do that.
  3. Check the live page Open the CSP checker and confirm the response header matches the draft.

Troubleshooting Common Issues

The site breaks after publishing

The preset blocked a script the theme needs.

  • Add that host to extra script hosts and publish again.
  • Do not add unsafe-eval unless a plugin requires it.
  • Re-run the CSP checker.

Validation Checklist

Post-fix validation

  • The live Content-Security-Policy matches the draft you intended.
  • You reviewed the unsafe-inline warning.
  • The builder did not change the site by itself.

FAQ

Does the builder publish the header?

No.

  • You copy the draft.
  • You add it on the server or CDN.
  • Then you check the live URL.