Nuxt · Scripts

NUXT0012Use Nuxt Scripts instead of useHead for third-party scripts

Flags third party usehead script in Nuxt project code before it leaks into runtime behavior.

Why it happens

Untrusted HTML and scripts are high-risk rendering surfaces. Keep them explicit, constrained, and routed through framework APIs that encode intent.

Fix

Remove third party usehead script, or move it to the Nuxt runtime/API that owns that behavior.

Example

Avoid third party usehead script

Before

useHead({
  script: [{ src: 'https://example.com/widget.js' }],
})

After

useHeadSafe({
  script: [{ src: trustedWidgetUrl }],
})

Verify the fix

Run only this rule after editing so the report stays focused on the diagnostic you are closing:

pnpm nuxt doctor --rules nuxt-scripts/no-third-party-usehead-script
Copyright © 2026