Errors / Blocked by the browser
Refused to load the script '…' because it violates the following Content Security Policy directive: "script-src …"
The site's security rules list which websites may send it scripts, and this one is not on the list.
The script, style or request it names does not load.
Why it happens
- A new vendor, a tag added in a tag manager, or a CDN host change that the
script-src(ordefault-src) list does not include. - The same rule for styles, images, fonts, frames and requests:
style-src,img-src,font-src,frame-src,connect-src.
How to fix it
- Add the host to the directive the message names, the narrowest one, not
default-src. - Check whether the script is wanted at all: a CSP refusal is sometimes the policy doing its job.
Whose problem it is
Usually the site's own code or settings.
Does your site have it?
Free, no account. We open your page and four more in a clean Chrome and list every error like this one, with the page and the click that caused it. How the free page check works.
Often seen with
- Refused to execute inline script (CSP)The site's own security rules forbid scripts written into the page, and one was.
- frame-ancestors violationA website shown inside this page does not allow being shown on this site.