Nuxt · NUXT0010

Use Nuxt Scripts for third-party scripts

Flags raw third party script tag in Nuxt project code before it leaks into runtime behavior.
NUXT0010vite-doctor/nuxt-scriptsscriptswarnSuggestion
nuxt-scripts/no-raw-third-party-script-tagsrc/rule-packs/nuxt/rules/nuxt-scripts.ts Upstream docs

Run this rule

pnpm nuxt doctor --rules nuxt-scripts/no-raw-third-party-script-tag

Why it matters

Untrusted HTML and scripts are high-risk rendering surfaces. Keep them explicit, constrained, and routed through framework APIs that encode intent.

Remove raw third party script tag, or move it to the Nuxt runtime/API that owns that behavior.

Example

Avoid raw third party script tag

Before

useHead({
  script: [{ src: 'https://example.com/widget.js' }],
})

After

useHeadSafe({
  script: [{ src: trustedWidgetUrl }],
})
Copyright © 2026