HeaderAudit

CSP media-src

Where audio and video may be loaded from.

Falls back to
default-src
Group
Fetch directives

Detail

Low risk in itself. The reason to set it is bandwidth and privacy rather than script execution โ€” an injected

Example

media-src 'self' https://cdn.example.com

Analyse a full policy โ†’ ยท Generate one โ†’