# Remove a risky value (/en/docs/platform/features/csp-builder/remove-risky-values)





The CSP builder keeps risky values that your pages load today, so the policy you deploy breaks nothing. This page removes one of them, such as [`'unsafe-inline'`](/en/blog/unsafe-inline-csp), after you change the code that needs it.

## Before you begin [#before-you-begin]

Make sure you have:

* A Content Security Policy (CSP) built with the CSP builder and deployed. Refer to [Get started](/en/docs/platform/features/csp-builder/get-started).
* Access to the code of the pages that load the value.

## Remove the value [#remove-the-value]

To remove a risky value:

1. In the website sidebar, go to **Builders** > **Content-Security-Policy**, and continue to the **Review sources** step.
2. In the flag filter, select the most severe risk level.
3. Select a row, then read the **Needed today, worth removing** callout. For example, it asks you to replace inline event handlers with `addEventListener` calls before you remove `'unsafe-inline'`.
4. Make that change in your code, and deploy it.
5. Wait until the reports cover a full period after your deploy, then run the builder again on that period.
6. Search for the value. Check that no **From reports** row remains for it in that directive, then select **Reject** on each of its rows.
7. On the **Deploy** step, copy the headers and deploy them.

<img alt="The details panel of unsafe-inline in script-src-attr, with the Needed today, worth removing callout asking to replace onclick handlers with addEventListener" src="__img0" width="1568" height="422" />

The value is gone from your policy, and its risk no longer appears in the grade on the **Deploy** step. If a **From reports** row remains in step 6, a page still needs it. Select the row and check **Pages where it happened**.

## Next steps [#next-steps]

* [Review table](/en/docs/platform/features/csp-builder/review-sources)
* [Nonces and unsafe-inline](/en/docs/platform/features/csp-builder/nonces-and-unsafe-inline)
* [CSP keywords](/en/docs/web-security/policies/content-security-policy/values/csp-keywords)
* [Hashes and nonces](/en/docs/web-security/policies/content-security-policy/values/csp-hashes-nonce)
