CSP & security-header monitoring

Know when your browser protections weaken—or block something important.

MetricPoints groups Content Security Policy violations, watches security headers and risky script activity, and preserves the evidence behind every change. Full-site monitoring shows whether the same event also affected availability, performance, or browser events.

Content Security Policy (CSP) is a browser protection layer that controls which scripts, images, frames, and other resources your site is allowed to load. It helps limit malicious code, risky third-party behavior, and unauthorized content.

Violation grouping Header health Risky scripts Change alerts

Included in every unified monitoring plan. Full Coverage adds raw diagnostic investigation.

Protection changed

New script source blocked

checkout.example.com · script-src

High impact

Blocked resource

https://payments.example-cdn.com/widget.js

Affected page

/checkout

First detected

After deployment

Browser events

Increased

Occurrences

Grouped incident

Review whether the new payment host is expected, then update the policy deliberately or investigate the deployment.

Illustrative incident using evidence captured by MetricPoints.

Continuous protection visibility

A policy is only useful if you know what it is doing in production.

CSP reports can be noisy and security headers can drift quietly. MetricPoints turns raw browser evidence into grouped, reviewable changes without hiding the technical detail developers need.

CSP violation grouping

Combine repeated reports by directive, source, page, and impact so patterns are visible.

Security-header health

Watch the browser-facing protections that can weaken during releases or configuration changes.

Risky-script visibility

Identify unexpected third-party sources and investigate what changed before trusting them.

Actionable incident history

Preserve detection, surrounding evidence, and recovery in one reviewable timeline.

One monitoring product

A blocked script might be protection working—or a customer journey breaking.

CSP evidence becomes more useful when it sits beside deployments, browser events, performance, uptime, SSL, and DNS changes. That context helps teams protect the site without blindly allowing every blocked source.

Explore complete website monitoring →

Browser events

Did a protected flow start failing for visitors?

Deployments

Did the source or policy change with a release?

Performance

Did a new third-party script slow key pages?

Infrastructure

Did DNS, SSL, or availability change at the same time?

Flexible installation

Fully managed CSP for any website

Use the hosted bootstrap script for a system-managed installation, or use the WordPress plugin where it fits. There is nothing to download for the hosted-script path.

Any website

Hosted bootstrap script

Install once with your site token and keep the integration system-managed.

<script async src="https://csp-heal.metricpoints.com/managed-csp.js?heal-token=YOUR_HEAL_TOKEN"></script>

WordPress

Plugin-assisted setup

Use the WordPress integration when plugin-based installation and configuration better match the site workflow.

  • ✓ Guided WordPress installation
  • ✓ CSP reporting connection
  • ✓ Access to policy tools and documentation
Explore the WordPress plugin →

Frequently asked questions

CSP and security monitoring, clearly explained

Does MetricPoints automatically loosen my CSP?+

No. Monitoring and recommendations do not silently allow new sources. Policy decisions should be reviewed against the captured evidence before changes are applied.

Will CSP monitoring prevent every attack?+

No single browser policy can prevent every threat. CSP reduces specific browser-side risks and provides valuable evidence, but it belongs inside a broader security and maintenance practice.

Is CSP monitoring a separate subscription?+

No. CSP, security headers, risky scripts, uptime, SSL, DNS, domains, browser events, and performance are signals inside the unified monitoring plans.

Which plan includes raw CSP reports?+

Every paid plan includes protection health and important incident summaries. Full Coverage and Full Coverage Team add raw event investigation, advanced filtering, and the deeper developer evidence.

Watch the protection—and the website it protects.

Start collecting CSP and security evidence in the same place as your availability, performance, infrastructure, and browser health.

Compare Unified Monitoring Plans

Choose Website Coverage for clear health summaries or Full Coverage for advanced diagnostics.