Skip to content

Errors / Blocked by the browser

Refused to execute inline script because it violates the following Content Security Policy directive: "script-src …"

The site's own security rules forbid scripts written into the page, and one was.

The blocked code does not run: often analytics, a chat widget or a form's behaviour.

Why it happens

  • A Content-Security-Policy whose script-src has no 'unsafe-inline', no nonce and no hash, and a <script> block or an onclick= attribute in the HTML.
  • A tag manager, an analytics snippet or a plugin that injects inline code the policy was not written for.
  • Refused to execute inline event handler is the same rule applied to onclick and friends.

How to fix it

  1. Give the inline script a nonce (<script nonce="…"> matching 'nonce-…' in the policy) or its hash.
  2. Move inline code and on…= handlers into files and addEventListener.
  3. Test a policy with Content-Security-Policy-Report-Only before enforcing it.

Whose problem it is

Usually the site's own code or settings.

Does your site have it?

Free, no account. We open your page and four more in a clean Chrome and list every error like this one, with the page and the click that caused it. How the free page check works.

Check only sites you run or have permission to check.

Often seen with