WPIntell

Source evidence

Regeneration for every page

CSP Friendly Security · support · 2023-02-16T19:19:00+00:00

complaintsentiment
highseverity
0.79relevance
1replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

5 / 19 rows with source links

26.3% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

14 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
marknopfler unresolved
Hi, great plugin!!! Based on web.dev “nonces must be regenerated for every page request and they must be unguessable.”, But I see the same nonce id for each page on site. Can you please add that function? Also I see no CSP generated on header. (– generate Content Security Policy header with all nonces and hashes + basics (base-uri ‘self’, google fonts, gravatar, maxcdn.bootstrapcdn…) Thanks! Also I see no CSP generated on header. (– generate Content Security Policy header with all nonces and hashes + basics (base-uri ‘self’, google fonts, gravatar, maxcdn.bootstrapcdn…) OK I see it on “Network” tab in DevTools. What about the generation of the nonce for every page? Thanks

Comments

1 shown
marknopfler 2023-02-17T11:13:00+00:00

Also I see no CSP generated on header. (– generate Content Security Policy header with all nonces and hashes + basics (base-uri ‘self’, google fonts, gravatar, maxcdn.bootstrapcdn…) OK I see it on “Network” tab in DevTools. What about the generation of the nonce for every page? Thanks