Nuxt · NUXT0055
Avoid unsafe scripts in useHead
Flags unsafe usehead script in Nuxt security code before it leaks into runtime behavior.
nuxt/security/no-unsafe-usehead-scriptsrc/rule-packs/nuxt/rules/nuxt/no-unsafe-use-head-script.ts Upstream docs Run this rule
pnpm nuxt doctor --rules nuxt/security/no-unsafe-usehead-script
Why it matters
Untrusted HTML and scripts are high-risk rendering surfaces. Keep them explicit, constrained, and routed through framework APIs that encode intent.
Recommended fix
Remove unsafe usehead script, or move it to the Nuxt runtime/API that owns that behavior.
Useful links
Example
Avoid unsafe usehead script
Before
useHead({
script: [{ src: 'https://example.com/widget.js' }],
})
After
useHeadSafe({
script: [{ src: trustedWidgetUrl }],
})