Injection Protection

Enterprise only

JavaScript injectionv3.9+

Detects arbitrarily injected JavaScript that is part of a cross site scripting attack and will execute in the browser. Uses the following regex for matching: <\s*script\b[^>]*>[^<]+<\s*/\s*script\s*>

Set up the plugin

Help us make these docs great!

Kong Developer docs are open source. If you find these useful and want to make them better, contribute today!