Content Security Policy is missing
helpfixmysites.com·Vercel / Next.js
Why it matters
Without a CSP, browsers have less guidance about which scripts and other resources a page is allowed to load. This can increase the impact of an injection flaw.
How to fix it
- Identify the scripts, styles, fonts, and API endpoints your site actually uses.
- Start with a report-only policy and review browser reports before enforcing it.
- Set a Content-Security-Policy response header with a restrictive default-src, script-src, object-src 'none', and base-uri 'self'.
RECOMMENDED CONFIGURATION
Content-Security-Policy: default-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'self'; upgrade-insecure-requestsHow to verify: CSP header check turns green