Header Genie CSP lab

Header Genie CSP lab

This homepage loads fonts, CSS, JavaScript, images, Bootstrap, and iframes so Content-Security-Policy can be tested with and without nonces.

Request nonce (empty if CSP is off): qDLThto5ftUfuZcqxjwq0g

Scripts

  • WordPress inline script with nonce blocked or pending
  • Head script with nonce blocked or pending
  • Head script without nonce blocked or pending
  • Footer script without nonce blocked or pending

Styles

This paragraph uses an inline style="" attribute (kept working via style-src-attr 'unsafe-inline').

This box is styled by a raw <style> tag with no nonce in source — Header Genie should stamp one automatically.

Google Fonts + Bootstrap CSS should restyle this page (hosts in style-src, plus nonce on stylesheet tags).

Images

Local WordPress logo Remote Wikimedia logo

Iframes

YouTube needs frame-src to allow https://www.youtube.com. Edit that on Header Genie → CSP.