Content-Security-Policy-Report-Only Cannot Be Declared Between META Tags Severity: Information Summary# Content-Security-Policy-Report-Only cannot be declared between META tags. Actions To Take# If you want to use one of the CSP in report only mode, you should declare it in response headers. Classifications# OWASP 2013-A5, CWE-16, OWASP 2017-A6, ISO27001-A.14.2.5, WASC-15 Invicti Security Insights Security tool integration can make or break secure development – ESG report New industry study: 70% of teams skip security steps What is privilege escalation and why is it important? Invicti Survey Reveals Executive Overconfidence in Web Security Integer Overflow Errors Vulnerability Index You can search and find all vulnerabilities Select Category Critical High Medium Low Best Practice Information OR Search Vulnerability Tags OWASP 2013-A5 OWASP 2017-A6 Related Vulnerabilities Insecure Transportation Security Protocol Supported (SSLv2) Insecure Transportation Security Protocol Supported (SSLv3) Open Policy Crossdomain.xml Detected Open Silverlight Client Access Policy Missing Content-Type Header