Your CSP is either missing, broken, or too loose. CSPFixer fetches your page, finds every resource, and generates a working policy.

Live URL fetch — scans your actual scripts, styles, fonts, and images. Generates a strict CSP for Nginx, Apache, Vercel, Cloudflare, and Express.

CSPFixer fetches your page and reads all resource URLs — nothing is stored