CSP Nonce Implementation Checklist
Assess and document your Content Security Policy nonce implementation to ensure best practices and compliance.
Project or Application Name
*
Project Owner or Responsible Contact
*
First Name
Last Name
Contact Email Address
*
example@example.com
Briefly describe the current Content Security Policy (CSP) configuration for this project.
*
How is the CSP nonce generated for each request?
*
Please Select
Cryptographically secure random value
Time-based or predictable value
Static or hardcoded value
Other
Are all inline tags using the correct nonce attribute?
*
Yes, all scripts use the correct nonce
Some scripts are missing the nonce
No scripts use the nonce
How is the nonce value passed from the backend to the frontend?
*
Please Select
Server-side templating
HTTP headers
JavaScript variable injection
Other
CSP Nonce Best Practices Compliance Checklist
*
Rows
Fully Implemented
Partially Implemented
Not Implemented
Nonces are unique per request
1
2
3
Nonces are applied to all inline scripts
4
5
6
Nonces are not reused across requests
7
8
9
No unsafe-inline is present in the CSP
10
11
12
Nonces are not exposed in client-side code
13
14
15
Have you tested the CSP implementation in different browsers and environments?
*
Yes, tested in all required environments
Tested in some environments only
Not tested
Have you enabled CSP violation reporting?
*
Yes, with reporting endpoint configured
No, reporting not enabled
Please describe any challenges, risks, or issues encountered during CSP nonce implementation.
Submit Checklist
Should be Empty: