Content-Security-Policy without unsafe-inline

[ad_1]

Working on getting a solid CSP on a number of WordPress sites. The biggest issue is that a number of plugins inject inline styles or scripts without nonces, which would require `unsafe-inline`. Tried with the recommended hashes that were given, but it looks like some of them were changing when generated.

The sites use a host of plugins, including WP Bakery, which does a load of injecting.

Saw this thread [here]), which lead to the casper tool. However, it just recommends removing all inline styles.

Any recommendations on how to create a CSP without `script-src: unsafe-inline`?

[ad_2]

 

This site will teach you how to build a WordPress website for beginners. We will cover everything from installing WordPress to adding pages, posts, and images to your site. You will learn how to customize your site with themes and plugins, as well as how to market your site online.

Buy WordPress Transfer