Skip to content

Errors / Blocked by the browser

Refused to load the script '…' because it violates the following Content Security Policy directive: "script-src …"

The site's security rules list which websites may send it scripts, and this one is not on the list.

The script, style or request it names does not load.

Why it happens

  • A new vendor, a tag added in a tag manager, or a CDN host change that the script-src (or default-src) list does not include.
  • The same rule for styles, images, fonts, frames and requests: style-src, img-src, font-src, frame-src, connect-src.

How to fix it

  1. Add the host to the directive the message names, the narrowest one, not default-src.
  2. Check whether the script is wanted at all: a CSP refusal is sometimes the policy doing its job.

Whose problem it is

Usually the site's own code or settings.

Does your site have it?

Free, no account. We open your page and four more in a clean Chrome and list every error like this one, with the page and the click that caused it. How the free page check works.

Check only sites you run or have permission to check.

Often seen with