# How to add analytics and pixel scripts avoiding Content Security Policy (XSS)

**URL:** <https://meta.discourse.org/t/how-to-add-analytics-and-pixel-scripts-avoiding-content-security-policy-xss/321022>\
**Category:** Data & reporting\
**Tags:** analytics\
**Created:** [August 10, 2024, 11:31am UTC](https://meta.discourse.org/t/how-to-add-analytics-and-pixel-scripts-avoiding-content-security-policy-xss/321022 "2024-08-10T11:31:56Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![illusionandcards](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/illusionandcards/32/306500_2.png) [@illusionandcards](https://meta.discourse.org/u/illusionandcards)\
**Post date:** [August 10, 2024, 11:31am UTC](https://meta.discourse.org/t/how-to-add-analytics-and-pixel-scripts-avoiding-content-security-policy-xss/321022/1 "2024-08-10T11:31:56Z")

</div>

Good day,

I’ve tried to add the Facebook Pixel script and Posthog analytics to my site with a custom component and editing the html from the default theme.

These are not working because of Content Security Policy. I even tried hashing the script with sha256, but I get this error when adding it to “content security policy script src”:

 ![image](https://global.discourse-cdn.com/meta/original/4X/6/8/1/681c4b26edc8eedc4a6e076fed9d127eb7b23284.png)

I’ve also read this topic: [Mitigate XSS Attacks with Content Security Policy](https://meta.discourse.org/t/mitigate-xss-attacks-with-content-security-policy/104243)

How can I avoid CSP on specific scripts?

Thank you!

---

_[View the full topic](https://meta.discourse.org/t/how-to-add-analytics-and-pixel-scripts-avoiding-content-security-policy-xss/321022)._
