Malware

Allowlist

Also called whitelist.

Allowlist is a list of hosts, URLs, or script hashes you agree to load, with everything else refused by default. It is the opposite stance to a blocklist: you name the good, not the bad.

How it is measured

You observe an allowlist by reading the config that enforces it: the `script-src` hosts in a CSP, a firewall egress rule, a WordPress plugin that restricts outbound calls, or a proxy rule. Count entries and compare them with what the page actually requests in the network tab.

The useful check is the diff. Crawl a page, list every third-party host it contacts, and subtract the allowlist. Anything left over is either a missing entry or an unapproved script, and both need an owner.

Worked example

A bakery's Astro site loads fonts from fonts.gstatic.com, a payment widget from js.stripe.com, and its own assets from cdn.bakery.example. The CSP allowlist holds exactly those three hosts. A compromised review plugin tries to pull a script from cdn-jquery-stats.top and the browser refuses it, logging one violation.

Three weeks later the owner adds a chat widget and forgets the allowlist. The widget loads nothing, support emails the owner, and the console shows two blocked requests to the chat vendor's CDN. One line added to the list fixes it.

How it differs

An allowlist names what may run and denies the rest. A blocklist names what may not run and permits the rest. The allowlist cannot be bypassed by a brand new malicious domain, but it breaks the page when a vendor changes hosts. The blocklist never breaks a page, but it is always one domain behind.

Common errors

Adding a wildcard like `*.cloudfront.net` and calling it an allowlist, since any attacker can rent a CloudFront subdomain. Allowing `unsafe-inline` and then wondering why injected script still runs. Never pruning entries for vendors you dropped two years ago. Allowlisting a host but not pinning the path or hash. Turning enforcement on without a report-only trial first.

In practice

Run your CSP in report-only mode for a week, collect the hosts it flags, and keep only the ones with a named owner on your team. Delete entries for tools you no longer use. Put the list in version control so a new host shows up as a reviewed diff, not a surprise.

See also

Blocklist, Content Security Policy

Sources

Count this on a real site.

Watch my website