External resources without Subresource Integrity — the fix
External scripts or stylesheets are loaded without Subresource Integrity (SRI) attributes, making them vulnerable to supply-chain attacks if the CDN or third-party host is compromised.
Where this fits: security in SEO
Security issues erode both rankings and trust. HTTPS has been a ranking signal since 2014, and browsers actively warn users away from insecure or mixed-content pages — a warning interstitial is a 100% bounce rate. Missing security headers rarely block indexing, but they widen your attack surface, and a hacked site (injected spam, malicious redirects) can be removed from results entirely. Security is the SEO work you do so you never have to do recovery work.
Why external resources without subresource integrity hurts your rankings
Without SRI, if an attacker compromises a CDN or third-party host, they can inject malicious code into your site. SRI ensures that browsers only execute resources whose content matches a cryptographic hash you specify, protecting against tampered files.
This is a medium-severity issue: individually modest, but it compounds — dozens of medium issues across hundreds of pages add up to a real quality deficit in how search engines assess the site.
How to fix it
Add integrity and crossorigin attributes to all external script and link tags. Generate the hash using the sha384 algorithm and include the crossorigin='anonymous' attribute.
<script src="https://cdn.example.com/lib.js" integrity="sha384-abc123..." crossorigin="anonymous"></script>Security best practices
- Serve everything over HTTPS and redirect HTTP with a single 301.
- Send HSTS, X-Content-Type-Options, and a Content-Security-Policy on every response.
- Eliminate mixed content — one insecure asset breaks the padlock.
- Keep dependencies and CMS plugins patched; most site hacks are known-CVE exploits.
- Monitor Search Console's security section — Google often knows you're hacked before you do.
The full library: SEO best practices, by category.
Frequently asked questions
What does "External resources without Subresource Integrity" mean?
External scripts or stylesheets are loaded without Subresource Integrity (SRI) attributes, making them vulnerable to supply-chain attacks if the CDN or third-party host is compromised.
Why does external resources without subresource integrity matter for SEO?
Without SRI, if an attacker compromises a CDN or third-party host, they can inject malicious code into your site. SRI ensures that browsers only execute resources whose content matches a cryptographic hash you specify, protecting against tampered files.
How do I fix external resources without subresource integrity?
Add integrity and crossorigin attributes to all external script and link tags. Generate the hash using the sha384 algorithm and include the crossorigin='anonymous' attribute.
How serious is this issue?
This is a medium-severity issue: individually modest, but it compounds — dozens of medium issues across hundreds of pages add up to a real quality deficit in how search engines assess the site. It belongs to the security family of checks.
How do I find every page affected by this on my site?
Run a free Dr Urls audit: it crawls your site, detects external resources without subresource integrity on every affected page, shows example URLs, and generates a ready-to-use fix task. Re-scan after fixing to verify the issue is gone.
Does your site have this issue?
A free Dr Urls audit crawls your site, finds every page affected by external resources without subresource integrity, and hands you a ready-made fix task.
Check my site free