HeaderAudit
C

youtube.com

Score 70/100 · scanned 2026-08-04

Content-Security-Policy

youtube.com sends an enforcing CSP. It is nonce-based and uses 'strict-dynamic'.

base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-jKIM0iDb5XWaWgxrYZP-xg' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval';report-uri https://csp.withgoogle.com/csp/youtube_main/strict, require-trusted-types-for 'script'
DirectiveSources
base-uri'self'
object-src'none'
script-src'report-sample' 'nonce-jKIM0iDb5XWaWgxrYZP-xg' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval'
report-urihttps://csp.withgoogle.com/csp/youtube_main/strict, require-trusted-types-for 'script'

Headers sent

HeaderValue
strict-transport-securitymax-age=31536000
x-frame-optionsSAMEORIGIN
x-content-type-optionsnosniff
permissions-policych-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*
cross-origin-opener-policysame-origin-allow-popups; report-to="youtube_main"
x-xss-protection0
serverESF

Re-scan live

This is a snapshot from 2026-08-04. Check it now: