Nuxt · Security

NUXT0056Use useHeadSafe for untrusted head values

Finds Nuxt security code that should use the supported useheadsafe for untrusted values pattern instead.

Why it happens

Values derived from routes, content, or users can inject unsafe head attributes when passed through unrestricted useHead().

Fix

Use the Nuxt-supported useheadsafe for untrusted values pattern instead.

Example

Use useHeadSafe for untrusted values

Before

const route = useRoute()
useHead({
  title: route.query.title as string,
})

After

const route = useRoute()
useHeadSafe({
  title: route.query.title as string,
})

Verify the fix

Run only this rule after editing so the report stays focused on the diagnostic you are closing:

pnpm nuxt doctor --rules nuxt/security/prefer-useheadsafe-for-untrusted-values
Copyright © 2026