Header Genie CSP lab
This homepage loads fonts, CSS, JavaScript, images, Bootstrap, and iframes so Content-Security-Policy can be tested with and without nonces.
Request nonce (empty if CSP is off):
qDLThto5ftUfuZcqxjwq0gScripts
- WordPress inline script with nonce blocked or pending
- Head script with nonce blocked or pending
- Head script without nonce blocked or pending
- Footer script without nonce
Styles
This paragraph uses an inline style="" attribute (kept working via style-src-attr 'unsafe-inline').
This box is styled by a raw <style> tag with no nonce in source — Header Genie should stamp one automatically.
Google Fonts + Bootstrap CSS should restyle this page (hosts in style-src, plus nonce on stylesheet tags).
Images
Iframes
YouTube needs frame-src to allow https://www.youtube.com. Edit that on Header Genie → CSP.