What Is Subresource Integrity (SRI)? Securing Code Loaded from a CDN
27 September 2026
Modern sites load some of their JavaScript and CSS from third-party sources (CDNs, analytics, widgets). This is convenient but carries a trust assumption: “the file from that source is the file I expect.” If that CDN or third party is compromised, malicious code can be injected into your site without your knowledge. Subresource Integrity (SRI) replaces that assumption with a cryptographic guarantee.
The problem: supply chain risk
When you add <script src="https://cdn.example/library.js">, the browser runs whatever is at that address, unquestioned. If the attacker compromises the CDN or intercepts the connection, they can change the file’s contents and run code in every visitor’s browser — even with no vulnerability on your server. The risk is in the supply chain.
The solution: an SRI hash
SRI lets you add the expected file’s cryptographic digest (hash) to the tag. The browser downloads the file, computes its digest, and compares it to yours; if they don’t match, it does not run the file.
<script src="https://cdn.example/library.js"
integrity="sha384-oqVuAfXRKap7fdgcCY5uykM6+R9GqQ8K/uxy9rx7HNQlGYl1kPzQho1wx4JwY8wC"
crossorigin="anonymous"></script>
integrity: the base64 digest with ansha384-(or sha256/sha512) prefix.crossorigin="anonymous": required for SRI to work on cross-origin files.
If the file is not exactly the expected version, the browser refuses to load it, so a compromised CDN’s modified file will not run.
How to apply it
- Generate the digest (many CDNs offer a ready SRI tag).
- Use a fixed version. SRI depends on file content; if you use a moving version like “latest,” a legitimate update breaks the site. Pin to a fixed version.
- Prioritise critical third-party scripts — payment, identity and common libraries.
Limits
SRI is strong but not everything: it is impractical for dynamically changing third-party scripts (personalised ads/analytics), and it does not audit a script’s own legitimate behaviour — only that the expected file loaded.
Summary
SRI turns the “the file I get is the file I expect” assumption about third-party code into a cryptographic check. Adding integrity + crossorigin to fixed-version, critical CDN scripts largely prevents a compromised supply chain from injecting code into your site.
Sources: MDN: Subresource Integrity, W3C SRI.
CyberTestify’s external surface scan reveals the third-party scripts your site loads and missing SRI/security headers.