Skip to content
All fingerprint checksAutomation surface

Content Security Policy is enforced

Check id csp-bypass

What an ordinary browser yields

The data: script is blocked.

What a detector infers

The audit excludes data: scripts. Execution despite script-src is direct CSP-bypass behavior.

How to resolve it

Do not enable Page.setBypassCSP or bypassCSP.

Nearby checks in Automation surface

See all 27 checks in Automation surface
Who builds this test

Clearcote is a browser built for fingerprint coherence

It is a Chromium fork, maintained by the same people who wrote this reference. It ships as a compiled browser rather than as a stealth script injected into someone else's — which is a description of how it is built, and is not an argument about how it behaves on this check.

This audit takes no position on how Clearcote scores on Automation surface checks, on this one, or anywhere else. It has no baseline corpus of other people's fingerprints to rank you against and no vendor scoreboard — nearly every check is self-referential, asking one browser the same question through two independent APIs and reporting whether both answers can be true at once. It runs identically on any browser, including ours. Run it on yours and read the result yourself.

See the other checks in Automation surface — the family csp-bypass belongs to.