Skip to content
WebsiteValidator
SecurityLow Detection only

No inline event handler attributes

SEC_NO_INLINE_EVENT_HANDLERS

Inline onclick/onload attributes cannot be covered by a nonce-based CSP, so their presence forces 'unsafe-inline' and blocks real XSS hardening.

  • Free, no signupNo account, no card
  • No AI in the score986 deterministic rules
  • Nothing publishedYour scans stay yours
  • Answers in secondsQuick scan, no browser

How this rule is weighted

Importance
4 / 10
How much this matters relative to other rules.
Confidence
RESEARCH
Backed by large-sample study or industry research, not a specification.
Severity
info
How the finding is presented when it fails.
Scoring
Excluded
Reported in the report, never penalised.

Impact is importance multiplied by the confidence tier’s weight — SPECIFICATION 1.0, RESEARCH 0.7, EMERGING 0.3, EXPERIMENTAL 0.1. Two rules backed by the same class of evidence therefore always carry the same weight, which is what makes the score reproducible rather than hand-tuned.

Questions about this rule

Does SEC_NO_INLINE_EVENT_HANDLERS affect my score?
No. It is a detection rule: it runs, appears in your report and never penalises you. "No inline event handler attributes" is information about the page rather than a defect - most pages are not expected to satisfy it.
What does RESEARCH confidence mean?
Backed by large-sample study or industry research, not a specification. Confidence is a declared tier rather than a per-rule number, so every rule backed by the same class of evidence carries the same weight - which is what makes the score reproducible instead of hand-tuned.
How do I check SEC_NO_INLINE_EVENT_HANDLERS on my own site?
Paste your URL into the box above and it runs only this rule, usually in a couple of seconds. It is also included in the Security checker and in a full scan.

Tags

  • security
  • csp
  • xss

Related Security rules

Run the Security checkerAll 986 rules