---
title: "Improve Security with Subresource Integrity (SRI) for CDN Scripts | bseoa"
description: "You're loading a script from a third-party source (like a CDN), but you're not verifying its contents. This is a security risk. If the CDN were ever compromise…"
image: "https://www.blackseoanalyzer.com/static/images/black-seo-analyzer-og-image.png"
canonical: "https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/missing-integrity-attribute"
language: "en"
---

# Improve Security with Subresource Integrity (SRI) for CDN Scripts

JavaScript Analyzer

## What is this warning?

You're loading a script from a third-party source (like a CDN), but you're not verifying its contents. This is a security risk. If the CDN were ever compromised, malicious code could be served to your users. Subresource Integrity (SRI) is a security feature that prevents this from happening.

## How to Fix This Issue

### How to Fix It

#### The Problem

```
<script src="https://cdn.example.com/library.js"></script>
```

#### The Solution

Add an `integrity` attribute containing a hash of the script file. You can usually get this hash from the CDN provider.

```
<script src="https://cdn.example.com/library.js" integrity="sha384-some-hash-value" crossorigin="anonymous"></script>
```

#### Why This Works

The `integrity` attribute tells the browser to check if the downloaded file matches the expected hash. If it doesn't match, the browser will refuse to run the script, protecting your site from malicious code injection.

### SEO Impact

This issue can affect your site's search engine rankings and user experience. Addressing it promptly helps ensure optimal performance and visibility in search results.

### Automatic Detection

bseoa automatically checks for this warning during site analysis, along with hundreds of other technical SEO issues.

## Other JavaScript Analyzer issues

- [Add crossorigin Attribute for Better Error Logging](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/missing-crossorigin-attribute)
- [Audit Third-Party Scripts for Performance and Security](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/third-party-script-loaded)
- [Avoid document.write for Better Performance and Security](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/document-write-usage)
- [Avoid eval() Due to Significant Security Risks](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/eval-usage)
- [Avoid Synchronous Scripts in <head> to Speed Up Rendering](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/synchronous-script-in-head)
- [Clarify Script Loading by Removing Redundant async and defer](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/redundant-async-and-defer)
- [Correct Unknown Script type for Proper Execution](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/unknown-script-type)
- [Deprecated JavaScript APIs: document.write, escape() and Inline Handlers](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/deprecated-api-usage)
- [Enhance Security by Loading All Scripts Over HTTPS](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/insecure-script-load)
- [Improve Code Maintainability by Avoiding Inline Event Handlers](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/inline-event-handler)
- [Improve Performance by Externalizing Large Inline Scripts](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/large-inline-script)
- [Modernize Your HTML by Removing Unnecessary Script type Attributes](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/unnecessary-type-attribute)
- [Optimize JavaScript Module Loading](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/module-without-async)
- [Optimize Loading of Blocking Third-Party Scripts](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/blocking-third-party-script)
- [Optimize Script Loading to Prevent Page Rendering Delays](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/render-blocking-script)
- [Preload Critical Scripts to Improve Page Load Performance](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/missing-preload-hint-for-script)
- [Remove console.log Statements from Production Code](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/console-log-usage)

## Ready to Unlock Your Site's Full SEO Potential?

Choose the license that fits your needs and start getting the deep, actionable insights you deserve.

[Download Free Trial](https://www.blackseoanalyzer.com/en/free-trial) [Purchase Single License](https://www.blackseoanalyzer.com/buy/single)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://www.blackseoanalyzer.com/#organization","name":"Fiscus Technology, LLC","url":"https://www.blackseoanalyzer.com/","logo":"https://www.blackseoanalyzer.com/static/images/black-seo-analyzer.png","founder":{"@type":"Person","name":"Seth Black"}},{"@type":"WebSite","@id":"https://www.blackseoanalyzer.com/#website","name":"bseoa","url":"https://www.blackseoanalyzer.com/","publisher":{"@id":"https://www.blackseoanalyzer.com/#organization"}},{"@type":"TechArticle","@id":"https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/missing-integrity-attribute#article","headline":"Improve Security with Subresource Integrity (SRI) for CDN Scripts","name":"Improve Security with Subresource Integrity (SRI) for CDN Scripts","description":"You're loading a script from a third-party source (like a CDN), but you're not verifying its contents. This is a security risk. If the CDN were ever compromised, malicious code could be served to your users. Subresource Integrity (SRI) is a security feature that prevents this from happening.","url":"https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/missing-integrity-attribute","image":{"@type":"ImageObject","url":"https://www.blackseoanalyzer.com/static/images/black-seo-analyzer-og-image.png","width":1200,"height":630},"author":{"@type":"Person","name":"Seth Black","url":"https://www.blackseoanalyzer.com/about"},"publisher":{"@id":"https://www.blackseoanalyzer.com/#organization"},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/missing-integrity-attribute"},"inLanguage":"en-US","keywords":"technical SEO, SEO warning, Seth Black&#39;s SEO Analyzer"},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.blackseoanalyzer.com/"},{"@type":"ListItem","position":2,"name":"Technical SEO Warnings","item":"https://www.blackseoanalyzer.com/en/technical-seo"},{"@type":"ListItem","position":3,"name":"Improve Security with Subresource Integrity (SRI) for CDN Scripts","item":"https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/missing-integrity-attribute"}]}]}
```
