Skip to main content
SecScannerSecScanner
Security ChecksFree ToolsPricingBlog
Get Started
Sign InGet Started

SRI Checker

Free online SRI checker. Scan any website to find third-party scripts and stylesheets loaded without a Subresource Integrity hash, verify the integrity attributes you already have, and see which CDN resources could be swapped under you. Instant results with the exact tag to copy.

Results in 1–3 minutes · Free · No signup required

What We Check

Missing integrity attribute detection
Third-party script and stylesheet inventory
crossorigin attribute verification
CDN-hosted resource risk assessment
Content Security Policy require-sri-for check
Mixed content and insecure resource detection

How It Works

1

Enter your website URL

2

We fetch your page and list every external script and stylesheet

3

Each third-party resource is checked for an integrity attribute

4

Resources with integrity are checked for a matching crossorigin attribute

5

You receive the unprotected resources with a ready-to-paste fixed tag

Security Checks Included

This tool runs the following security checks on your website

Subresource Integrity (SRI)Mixed ContentContent Security Policy (CSP)Vulnerable JS Libraries

Frequently Asked Questions

What is an SRI checker?
An SRI checker is a free online tool that fetches your page and inspects every external script and stylesheet for a Subresource Integrity hash. It reports which third-party resources load without an integrity attribute, which have one but are missing crossorigin, and what the corrected tag should look like.
How do I check Subresource Integrity on my website?
Enter your website URL in the SRI checker above. We fetch the page, list every external script and stylesheet, and flag each one that loads from a third-party origin without an integrity attribute — no signup needed.
What is Subresource Integrity (SRI)?
Subresource Integrity is a browser feature that pins a third-party file to a cryptographic hash. You add integrity="sha384-…" to a script or link tag, and the browser refuses to execute the file if its contents no longer match the hash — which is what stops a compromised CDN from serving malicious code to your visitors.
Why does integrity need the crossorigin attribute?
An integrity attribute on a cross-origin resource only works when the request is made in CORS mode. Without crossorigin="anonymous" the browser cannot read the response to verify the hash, so it blocks the resource outright — the tag looks protected but the script silently never loads.
How do I generate an SRI hash?
Run openssl dgst -sha384 -binary file.js | openssl base64 -A on the exact file you serve, then use the output as integrity="sha384-<output>". Most CDNs (jsDelivr, cdnjs, unpkg) also publish a ready-made integrity attribute next to each file, which is the safer route because it is generated from the file they actually serve.
Do I need SRI on my own scripts?
Usually not. SRI protects against a file changing on an origin you do not control — a CDN, a widget vendor, an analytics host. On self-hosted files it mostly gets in the way, because every deploy that changes the file also has to update the hash or the page breaks.
Is this SRI checker free?
Yes, our SRI checker is completely free. It's part of SecScanner's free toolkit that runs 62 security checks covering SSL, HTTP headers, DNS, cookies, and content.

Ready to Check Your Website?

Run a free security scan now and get instant results with actionable fix recommendations.

Results in 1–3 minutes · Free · No signup required

Product

  • Security Checks
  • Free Tools
  • SSL Checker
  • Vulnerability Scanner
  • Email Security
  • Pricing
  • Compliance
  • Security Reports

Popular Checks

  • CSP Check
  • HSTS Check
  • TLS Version Check
  • SSL Expiry Check
  • SPF/DKIM/DMARC Check
  • Cookie Security Check
  • JS Vulnerability Scan
  • OCSP Stapling Check

Resources

  • Blog
  • Glossary
  • Mozilla Observatory Alternative
  • ImmuniWeb Alternative
  • Contact

Legal

  • Terms of Use
  • Privacy Policy
  • Refund Policy
  • Cookie Policy

© 2025-2026 SecScanner. All rights reserved.