Nuxt · NUXT0055

Avoid unsafe scripts in useHead

Flags unsafe usehead script in Nuxt security code before it leaks into runtime behavior.
NUXT0055vite-doctor/nuxtsecurityerrorSuggestion

Run this rule

pnpm nuxt doctor --rules nuxt/security/no-unsafe-usehead-script

Why it matters

Untrusted HTML and scripts are high-risk rendering surfaces. Keep them explicit, constrained, and routed through framework APIs that encode intent.

Remove unsafe usehead script, or move it to the Nuxt runtime/API that owns that behavior.

Example

Avoid unsafe usehead script

Before

useHead({
  script: [{ src: 'https://example.com/widget.js' }],
})

After

useHeadSafe({
  script: [{ src: trustedWidgetUrl }],
})
Copyright © 2026