Termly does not provide Subresource Integrity (SRI) hashes for its scripts. If a security scanner such as SecurityScorecard flags Termly's <script> tags for a missing integrity attribute, this article explains why and what to use instead.
Why Termly doesn't provide SRI hashes
Termly's scripts are updated in place as part of normal platform operations. An SRI hash pins your page to one exact version of a file. After our next release, the file no longer matches the hash, and the browser refuses to load it.
For the consent banner, that means no banner and no consent collection on your site. That is a bigger compliance risk than the scanner finding SRI is meant to address. This is a deliberate decision, not a missing feature, and applies to every Termly customer.
Use Content Security Policy (CSP) allowlisting instead
A Content Security Policy lets you restrict which domains can load scripts and make connections on your site, without tying validation to a single script version. CSP is set on your side, through the Content-Security-Policy HTTP response header, usually at your web server, CDN, or security gateway.
Add these directives for Termly:
| Directive | Value |
|---|---|
script-src | app.termly.io |
connect-src | *.termly.io |
Use the *.termly.io wildcard rather than listing individual subdomains. Termly may add new services on other termly.io subdomains over time, and your account's consent endpoint is chosen at runtime. A narrower list could block those requests without warning and break consent saving on your site.
If your CSP uses a nonce with 'strict-dynamic'
Termly works with this pattern. Add the nonce to the Termly <script> tag itself. 'strict-dynamic' then trusts the scripts Termly loads from there, so no other changes are needed.
Requesting a scanner exception
If your scanner allows exceptions, you can share this article as Termly's official position. A missing integrity attribute on scripts from app.termly.io can be treated as an accepted exception, with CSP allowlisting as the compensating control.
Need a signed statement for your security team or scanner? Contact Termly Support and we'll provide one.