Hello!
Our client recently sent us a report regarding content security policy issues.
Here you can find the details:
Directive: default-src
Issue 1: unsafe-inline allows the execution of unsafe in-page
scripts and event handlers.
Issue 2: unsafe-eval allows the execution of code injected
into DOM APIs such as eval().
Issue 3: https: URI in default-src allows the execution of
unsafe scripts.
We noticed that the CSP policies also affects WPML.
Have you already worked on these security issues? Do you have an hook we can use to set a nonce or hash to styles and scripts generated by your plugins?
Thanks,
Emanuela
hello! I still need assistance. First of all i need to backup the staging site and ask my client if I can send you the credentials you need. I'll be back to you as soon as I receive the authorization.
Many thanks.
E