RW & addons in general, CSP3 and unsafe-inline Javascripts

So I tested a few sites on the Mozilla CSP test site… https://observatory.mozilla.org/

Here are some test results…

  • Mozilla - B (HA! Its their own tool!!!)
  • Amazon - D
  • Apple - C-
  • Google - D
  • Bank of America - F
  • Chase - D
  • PayPal - B
  • Barclays - F

As you can see from the grades above, the grade that these online testers provide really need to be taken with a grain of salt (ok, maybe a bucket of salt).

1 Like