HeaderAudit
F

letsencrypt.org

Score 0/100 · scanned 2026-08-04

Content-Security-Policy

letsencrypt.org sends an enforcing CSP. It is allowlist-based.

default-src 'none'; font-src 'self' https://doublethedonation.com https://rsms.me http://rsms.me ; style-src 'self' 'unsafe-inline' https://donorbox.org https://doublethedonation.com https://rsms.me http://rsms.me ; script-src 'unsafe-eval' 'unsafe-inline' 'self' data: https://www.google-analytics.com https://www.googleadservices.com https://www.googletagmanager.com https://cdn.jsdelivr.net http://cdn.jsdelivr.net https://googleads.g.doubleclick.net https://donorbox.org https://doublethedonation.com https://js.stripe.com https://jspm.dev https://js.stripe.com/v3/ https://sdks.shopifycdn.com https://www.paypal.com https://www.paypalobjects.com https://widget.thegivingblock.com https://*.shift4.com ; img-src 'self' data: blob: https://www.google-analytics.com https://donorbox.org https://doublethedonation.com https://*.paypal.com https://www.paypalobjects.com https://ak2s.abmr.net https://ak1s.abmr.net https://www.google.com https://cdn.shopify.com https://v.shopify.com ; frame-src https://donorbox.org https://www.youtube.com https://www.youtube-nocookie.com https://bid.g.doubleclick.net https://js.stripe.com/v3/ https://js.stripe.com/v2/ https://www.paypal.com https://outreach.abetterinternet.org https://app.netlify.com https://widget.thegivingblock.com/ ; connect-src 'self' https://d4twhgtvn0ff5.cloudfront.net/ https://donorbox.org https://doublethedonation.com https://letsencrypt-merch.myshopify.com https://monorail-edge.shopifysvc.com https://www.paypal.com https://www.google-analytics.com ; frame-ancestors 'none';
DirectiveSources
default-src'none'
font-src'self' https://doublethedonation.com https://rsms.me http://rsms.me
style-src'self' 'unsafe-inline' https://donorbox.org https://doublethedonation.com https://rsms.me http://rsms.me
script-src'unsafe-eval' 'unsafe-inline' 'self' data: https://www.google-analytics.com https://www.googleadservices.com https://www.googletagmanager.com https://cdn.jsdelivr.net http://cdn.jsdelivr.net https://googleads.g.doubleclick.net https://donorbox.org https://doublethedonation.com https://js.stripe.com https://jspm.dev https://js.stripe.com/v3/ https://sdks.shopifycdn.com https://www.paypal.com https://www.paypalobjects.com https://widget.thegivingblock.com https://*.shift4.com
img-src'self' data: blob: https://www.google-analytics.com https://donorbox.org https://doublethedonation.com https://*.paypal.com https://www.paypalobjects.com https://ak2s.abmr.net https://ak1s.abmr.net https://www.google.com https://cdn.shopify.com https://v.shopify.com
frame-srchttps://donorbox.org https://www.youtube.com https://www.youtube-nocookie.com https://bid.g.doubleclick.net https://js.stripe.com/v3/ https://js.stripe.com/v2/ https://www.paypal.com https://outreach.abetterinternet.org https://app.netlify.com https://widget.thegivingblock.com/
connect-src'self' https://d4twhgtvn0ff5.cloudfront.net/ https://donorbox.org https://doublethedonation.com https://letsencrypt-merch.myshopify.com https://monorail-edge.shopifysvc.com https://www.paypal.com https://www.google-analytics.com
frame-ancestors'none'

Headers sent

HeaderValue
strict-transport-securitymax-age=31536000
x-frame-optionsDENY
x-content-type-optionsnosniff
referrer-policyno-referrer
permissions-policygeolocation=(), midi=(), sync-xhr=(), microphone=(), camera=(), magnetometer=(), gyroscope=(), fullscreen=(self), interest-cohort=()
x-xss-protection1; mode=block
serverNetlify

Critical findings

script-src allows 'unsafe-inline', which permits inline <script> blocks and event handlers. This defeats the main purpose of CSP.Replace it with a per-response nonce, or hashes for each inline script.
script-src allows data: URIs, which lets an attacker inline arbitrary script through a data URL.Remove data: from script-src.

Re-scan live

This is a snapshot from 2026-08-04. Check it now: