3 ms·
Hi, my web site gets three warnings: fail: X-Frame-Options header is not set. fail: CSP header is not set. fail: Inline JavaScript was found. and a score of
by fduran 13y ago
Hi, my web site gets three warnings:
fail: X-Frame-Options header is not set.
fail: CSP header is not set.
fail: Inline JavaScript was found.
and a score of 0% (scan id: a4c9db4c-17fc-4599-9cac-7f3c7f92c9d9 ) and cnn.com gets the same three warnings plus an extra one and a site grade of 36%.
- aquark 13y agoWhat's the intrinsic risk in inline javascript? My site uses it to provide page specific data and I'm not really seeing any obvious security risks with it ... then again most security risks aren't obvious!
- cddotdotslash 13y agoThere's not a risk directly, but it conflicts with newer CSP (Content Security Policy) headers. So you can set CSP to only allow external JS (to prevent XSS through a parameter echoed on your page, for example). Then, it will block any inline JS (including the injection). So it's not a security risk, just something that helps prevent XSS through CSP.