Content Security Policy Builder

'unsafe-inline' in script-src removes essentially all the XSS protection CSP exists to give. The audit says so.

More developer tools