CSP is an added layer of security that helps to mitigate mainly Cross-site Scripting attacks.

There is no direct impact of not implementing CSP on your website. However, if your website is vulnerable to a Cross-site Scripting attack CSP can prevent successful exploitation of that vulnerability. By not implementing CSP you’ll be missing out this extra layer of security.

Some Advice for Common Problems

  1. Enable CSP on your website by sending the Content-Security-Policy in HTTP response headers that instruct the browser to apply the policies you specified.
  2. Apply the whitelist and policies as strict as possible.

