Security fix guide
Subresource Integrity Missing for Third-Party Assets
Third-party scripts and stylesheets are loaded without integrity attributes (SRI). If a CDN is compromised, malicious code could be injected.
Issue ID: SEC-SRI-001
Severity: minor
Impact: Low
Effort: S
Use this article when
- You need deeper remediation guidance than the issue card can show.
- You want CMS-specific steps before handing the fix to a developer.
- You want a repeatable re-check path after shipping the change.
What this issue is
Third-party scripts and stylesheets are loaded without integrity attributes (SRI). If a CDN is compromised, malicious code could be injected.
Why it matters
Third-party scripts and stylesheets are loaded without integrity attributes (SRI). If a CDN is compromised, malicious code could be injected. This affects browser trust signals and whether visitors feel safe submitting contact details.
How we detect it
- FreeSiteAudit flags this issue when the rule for SEC-SRI-001 fails and the page evidence points to Dom body.
- You can usually confirm this by checking the page source or the relevant page settings inside your CMS.
Evidence examples
Check the affected page source, rendered output, or relevant CMS setting to confirm the missing or incorrect element.
How to fix it
- 1Add integrity="sha384-..." and crossorigin="anonymous" to third-party <script> and <link> tags
- 2Generate hashes using srihash.org
How to re-check it
- Inspect third-party script/link tags and confirm integrity attributes are present
Related tools
This issue is best verified with the full FreeSiteAudit crawl rather than a single-point mini tool.