🔍 Overview
When you paste code containing tags into the Custom HTML Content field inside OTTO SEO, the platform's Web Application Firewall (WAF) may strip or block that content before it is saved or deployed. This article explains why this happens, how to deliver JSON-LD structured data safely, and what to do if you need to inject other types of scripts.
⚙️ Why the WAF Blocks Script Tags
Search Atlas runs a WAF in front of all user-submitted content fields to protect the platform and your site from cross-site scripting (XSS) and code-injection attacks. The WAF applies a blanket rule that flags any raw tag submitted through form inputs — including the Custom HTML Content field in OTTO SEO. This behavior is intentional and by design; it is not a bug specific to your account.
The WAF rule affects:
- Inline blocks (e.g. JSON-LD wrapped in )
- External script references (e.g. )
- Any HTML attribute that contains JavaScript event handlers
✅ Supported Way to Deliver JSON-LD Structured Data
JSON-LD is the recommended format for structured data, and there is a dedicated, WAF-safe path to deploy it through OTTO SEO without using the Custom HTML Content field.
- Open OTTO SEO → All Sites (SEO Automation) from the left sidebar (or navigate to /seo-automation-v3).
- Select the page or template you want to add structured data to.
- Look for the Schema / Structured Data section within the OTTO SEO page settings.
- Enter your JSON-LD object directly into the structured data editor — without the wrapping tags. OTTO automatically wraps your payload in the correct tag and injects it into the page head at deploy time, bypassing the WAF rule entirely.
- Save and deploy your changes as normal.
This is the only fully supported method for delivering JSON-LD through OTTO SEO. It ensures your structured data passes WAF validation and is rendered correctly by search engine crawlers.
📋 What About Tracking Pixels and Other Scripts?
Tracking pixels and third-party scripts (e.g. Google Tag Manager, Meta Pixel, TikTok Pixel) should not be added through the Custom HTML Content field. The recommended approach is:
- Google Tag Manager (GTM): Install the GTM container snippet through your site's theme or CMS header/footer injection settings, then manage all pixels and scripts inside GTM. OTTO SEO can detect an existing GTM installation and will not duplicate it.
- Native pixel fields: Some integrations within Search Atlas have dedicated pixel ID fields — use those instead of pasting raw script tags.
- CMS-level injection: For scripts that must be on every page, add them at the theme or template level in your CMS (e.g. WordPress header.php, Shopify theme settings) rather than through OTTO's content fields.
🚫 What Is Not Supported
- Raw tags pasted into the Custom HTML Content field — these will be blocked by the WAF and will not appear on your site.
- Account-level WAF exceptions for individual customers — the WAF rules are platform-wide and cannot be disabled for specific accounts.
- Encoding workarounds (e.g. Base64-encoded scripts or HTML entity encoding) — the WAF is designed to detect obfuscated script patterns and will still block them.
💡 Quick Troubleshooting Checklist
- JSON-LD not appearing on your page? Confirm you are using the dedicated Schema / Structured Data section in OTTO SEO, not the Custom HTML Content field.
- Structured data editor not visible? Make sure your OTTO SEO plan includes schema automation. Check your subscription or contact support.
- Pixel not firing? Verify the pixel is installed at the CMS or GTM level, not through a Custom HTML field.
- Custom HTML content disappearing after save? This is the WAF removing blocked tags. Remove any tags from your content before saving.
🆘 Need More Help?
If you need further assistance, open the chat widget in the bottom-right corner of the platform and type human teammate to be connected with a member of our team.