Content-Security-Policy-Report-Only Cannot Be Declared Between META Tags

Severity: Information
Summary#

Content-Security-Policy-Report-Only cannot be declared between META tags.

Actions To Take#
  • If you want to use one of the CSP in report only mode, you should declare it in response headers.

Invicti Logo

Dead accurate, fast & easy-to-use Web Application Security Scanner

Get a demo