Nuxt · Scripts

NUXT0011Use Nuxt Scripts instead of raw app.head scripts

Flags third party config script in Nuxt project code before it leaks into runtime behavior.

Why it happens

Untrusted HTML and scripts are high-risk rendering surfaces. Keep them explicit, constrained, and routed through framework APIs that encode intent.

Fix

Remove third party config script, or move it to the Nuxt runtime/API that owns that behavior.

Example

Avoid third party config script

Before

useHead({
  script: [{ src: 'https://example.com/widget.js' }],
})

After

useHeadSafe({
  script: [{ src: trustedWidgetUrl }],
})

Verify the fix

Run only this rule after editing so the report stays focused on the diagnostic you are closing:

pnpm nuxt doctor --rules nuxt-scripts/no-third-party-config-script
Copyright © 2026