Errors / Blocked by the browser
Refused to execute inline script because it violates the following Content Security Policy directive: "script-src …"
The site's own security rules forbid scripts written into the page, and one was.
The blocked code does not run: often analytics, a chat widget or a form's behaviour.
Why it happens
- A
Content-Security-Policywhosescript-srchas no'unsafe-inline', no nonce and no hash, and a<script>block or anonclick=attribute in the HTML. - A tag manager, an analytics snippet or a plugin that injects inline code the policy was not written for.
Refused to execute inline event handleris the same rule applied toonclickand friends.
How to fix it
- Give the inline script a nonce (
<script nonce="…">matching'nonce-…'in the policy) or its hash. - Move inline code and
on…=handlers into files andaddEventListener. - Test a policy with
Content-Security-Policy-Report-Onlybefore enforcing it.
Whose problem it is
Usually the site's own code or settings.
Does your site have it?
Free, no account. We open your page and four more in a clean Chrome and list every error like this one, with the page and the click that caused it. How the free page check works.
Often seen with
- Refused to load the script (CSP)The site's security rules list which websites may send it scripts, and this one is not on the list.