
Taskade was tested and 159 issues were detected across the site. The most critical finding was: CSP is in report-only mode; external scripts from multiple domains are not enforced. Issues span Security, Performance, A11y, Other categories. Persona feedback rated Visual highest (9/10) and Accessibility lowest (6/10).







[INFO] Loading the script 'https://us-assets.i.posthog.com/array/phc_6eC2U3HVeurZjP15Q3yFLkkugQ1cviGuI8bDizB8T1n/config.js' violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' 'unsafe-inline' https://ajax.cloudflare.com https://challenges.cloudflare.com https://js.driftt.com https://widget.drift.com https://www.googletagmanager.com https://www.google-analytics.com https://ssl.google-analytics.com https://checkout.stripe.com https://js.stripe.com https://www.youtube.com https://player.vimeo.com https://fast.wistia.com https://r.wdfl.co https://public.profitwell.com https://cdn.firstpromoter.com https://canny.io https://pa.taskade.com https://unicorn.taskade.workers.dev https://static.cloudflareinsights.com". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback. The policy is report-only, so the violation has been logged but no further action has been taken.Connecting to 'https://us.i.posthog.com/flags/?v=2&config=true&ip=0&_=1774475013086&ver=1.347.2&compression=base64' violates CSP connect-src directive; The policy is report-only, so no action taken. Also connects to Google Analytics collection endpoints which violate connect-src in the same report-only manner.https://www.googletagmanager.com/gtag/js?id=G-WWJTNN1SFE[INFO] Connecting to 'https://analytics.google.com/g/collect?v=2&tid=G-WWJTNN1SFE>m=45je63o0v879630057za200zd879630057&_p=1774475013077&_gaz=1&gcd=13l3l3l3l1l1&npa=0&dma=0&cid=617823860.1774475013&ul=en-us&sr=800x600&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&are=1&frm=0&pscdl=noapi&_eu=AAAAAGA&_s=1&tag_exp=103116026~103200004~115938465~115938469~116024733~117484252~117884344~118199988&sid=1774475013&sct=1&seg=0&dl=https%3A%2F%2Fwww.taskade.com%2F&dt=AI%20App%20Builder%3A%20Vibe%20Code%20Apps%2C%20AI%20Agents%20%26%20Workflow%20Automations%20%7C%20Taskade&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=912' violates the following Content Security Policy directive: "connect-src 'self' https://www.google-analytics.com https://*.googleapis.com https://api.rudderlabs.com https://hosted.rudderlabs.com https://rudderstack.taskade.cloud https://api.stripe.com https://checkout.stripe.com https://sentry.io wss: https://cn2bi8ujy8.execute-api.us-east-1.amazonaws.com https://taskade-files.s3.us-east-1.amazonaws.com https://files.taskade.com https://vimeo.com https://fast.wistia.com https://*.loom.com https://www2.profitwell.com https://api.canny.io https://companion.taskade.com"https://analytics.google.com/g/collect?v=2&tid=G-WWJTNN1SFE>m=45je63o0v879630057za200zd879630057&_p=1774475013077&_gaz=1&gcd=13l3l3l3l1l1&npa=0&dma=0&cid=617823860.1774475013&ul=en-us&sr=800x600&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&are=1&frm=0&pscdl=noapi&_eu=AAAAAGA&_s=1&tag_exp=103116026~103200004~115938465~115938469~116024733~117484252~117884344~118199988&sid=1774475013&sct=1&seg=0&dl=https%3A%2F%2Fwww.taskade.com%2F&dt=AI%20App%20Builder%3A%20Vibe%20Code%20Apps%2C%20AI%20Agents%20%26%20Workflow%20Automations%20%7C%20Taskade&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=912