← All bot detection signals

2. Evasion, Debugger, & Anti-Stealth Traps

CSP Bypass

Detection approach

Content Security Policy (CSP) bypass detected. The browser successfully loaded dynamic scripts that violate server-provided security headers, a setting commonly disabled in scraping scripts to force cross-origin requests.

How this helps detect bots

This signal is assessed with other independent session, browser, and network evidence. A single anomaly is a lead, not a verdict; corroborating anomalies make automated traffic more likely.

Legitimate traffic to consider

Misconfigured browser security levels or aggressive privacy extension scripts bypass.

BotRefund — best bot protection for your website