WPIntell

no-unsafe-inline

No unsafe-inline

No unsafe-inline helps you to build a Content Security Policy avoiding to use 'unsafe-inline' and 'unsafe-hashes'.

200
11.8K
5.0
1
18
5

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

87 / 128 rows with source links

68.0% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

41 rows with no attached evidence

0 rows have source counts but still need direct links.

Download Momentum

180 days
143 158 -9.5% 1.1K

Source Evidence

Open evidence explorer
complaint support · high severity · relevance 1.0
Compatibility with caching & JS/CSS optimization plugins

Compatibility with caching & JS/CSS optimization plugins: users show security, bugs, compatibility pain that may indicate a product gap.

Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
Proof Blocked card complete multisite and site-portfolio operations Evidence linked to opportunity
Compatibility with caching & JS/CSS optimization plugins Hi, I’m wondering if some caching & JS/CSS optimization plugins are known to work when “No unsafe-inline” plugin is enabled?
complaint support · high severity · relevance 0.98
CSP Issue in WordPress with No Unsafe Inline Plugin & .htaccess

CSP Issue in WordPress with No Unsafe Inline Plugin & .htaccess: users show security, bugs, compatibility pain that may indicate a product gap.

Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
Proof Blocked card complete multisite and site-portfolio operations Evidence linked to opportunity
CSP Issue in WordPress with No Unsafe Inline Plugin & .htaccess Hello everyone, I’m experiencing an issue with Content Security Policy (CSP) in WordPress while using the No Unsafe Inline plugin.
complaint support · high severity · relevance 0.96
Google youTube, reCaptcha integrity failure

Google youTube, reCaptcha integrity failure: users show security, bugs, support pain that may indicate a product gap.

Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
Proof Blocked card complete multisite and site-portfolio operations Evidence linked to opportunity
Google youTube, reCaptcha integrity failure reCaptcha error Failed to find a valid digest in the ‘integrity’ attribute for resource ‘ https://www.google.com/recaptcha/api.js?hl=en&ver=6.9.1#038;render=explicit’ ; with computed SHA-256 integrity ‘k14ryYrM1KYcKsCdkuqoQDoGn480m4fP1lZEZmaICo8=’.
complaint support · high severity · relevance 0.96
problems with no-unsafe .js

problems with no-unsafe .js: users show security, bugs, missing feature pain that may indicate a product gap.

Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
Proof Blocked card complete multisite and site-portfolio operations Evidence linked to opportunity
problems with no-unsafe .js I’m having problems getting this one to work: no-unsafe-inline-fix-style.min.js?ver=1.2.2:2 [Report Only] Refused to apply inline style because it violates the following Content Security Policy directive: “style-src https://pro.fontawesome.com ‘nonce-f729f65c7d6625f00e4266825df72b094d37e64c6e7ad38d8590bc6deab4c949’ ‘report-sample'
complaint support · high severity · relevance 0.96
Fatal error after upgrading to v1.2.3

Fatal error after upgrading to v1.2.3: users show bugs, compatibility, migration pain that may indicate a product gap.

Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
Proof Blocked card complete multisite and site-portfolio operations Evidence linked to opportunity
Fatal error after upgrading to v1.2.3 Hi, Following an update to v1.2.3, my sites are down with the following error : Fatal error: Uncaught TypeError: Cannot assign __PHP_Incomplete_Class to property Rubix\ML\Classifiers\KNearestNeighbors::$kernel of type Rubix\ML\Kernels\Distance\Distance in F:\apps\www.test.com\wp-content\plugins\no-unsafe-inline\vendor\ru
mixed support · high severity · relevance 0.95
TrustedHTML throws an error in no-unsafe-inline-fix-style.js

TrustedHTML throws an error in no-unsafe-inline-fix-style.js: users show security, bugs, compatibility pain that may indicate a product gap.

Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
Proof Blocked card complete multisite and site-portfolio operations Evidence linked to opportunity
TrustedHTML throws an error in no-unsafe-inline-fix-style.js One of my plugins is loading reCAPTCHA, which is throwing an e.replace is not a function error in the no-unsafe-inline-fix-style.min.js script, relating to reCAPTCHA trying to add its badge HTML.
mixed support · high severity · relevance 0.94
Enable tag capture only on frontend

Enable tag capture only on frontend: users show security, bugs, missing feature pain that may indicate a product gap.

Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
Proof Blocked card complete multisite and site-portfolio operations Evidence linked to opportunity
The plugin ‘Settings’ tab allows us to disable enforcing CSP-policy in WordPress admin.
complaint support · high severity · relevance 0.91
Concerns about nginx deployment

Concerns about nginx deployment: users show bugs, support, setup pain that may indicate a product gap.

Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
Proof Blocked card complete multisite and site-portfolio operations Evidence linked to opportunity
Kudos to you for trying to resolve an issue that should really be of top concern to the entire WordPress ecosystem!
complaint support · high severity · relevance 0.91
CSP Headers not loading POST PLUGIN UPDATE

CSP Headers not loading POST PLUGIN UPDATE: users show security, bugs, support pain that may indicate a product gap.

Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
Proof Blocked card complete multisite and site-portfolio operations Evidence linked to opportunity
In spite of have turned on the CSP Protection, all the CSP Checkers like https://securityheaders.com/ https://observatory.mozilla.org/ https://csp-evaluator.withgoogle.com/ https://csper.io/evaluator gives out error “Cannot fetch CSP headers!” or “unable to evaluate url: no policies found at URL” The page I need help with: [ log in to see the link] Hi, Post
complaint support · high severity · relevance 0.91
CSP Blocks no-unsafe-inline-fix-style.min.js

CSP Blocks no-unsafe-inline-fix-style.min.js: users show security, bugs, support pain that may indicate a product gap.

Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
Proof Blocked card complete multisite and site-portfolio operations Evidence linked to opportunity
CSP Blocks no-unsafe-inline-fix-style.min.js Hi, First of all, thank you for this plugin, it has helped us easily manage the CSP headers.

Competitor Context

6 shown
Cookies and Content Security Policy praise owner · intel 72.7 · weakness 49.0
praise owner
1 unresolved support thread(s) 7 collected complaint signal(s) security compatibility 2 source links Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and compliance-sensitive marketing teams · Wedge: audit GDPR consent state, tracking disclosures, cookie behavior, and compliance drift
Content Security Policy Manager praise owner · intel 71.8 · weakness 57.3
praise owner
stale update history 6 collected complaint signal(s) support bugs 2 source links Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
GD Security Headers praise owner · intel 67.6 · weakness 47.0
praise owner
16 collected complaint signal(s) missing feature security 2 source links Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Security Header Generator praise owner · intel 51.5 · weakness 24.7
praise owner
2 collected complaint signal(s) security bugs 2 source links Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
HTTP Security Header praise owner · intel 48.8 · weakness 22.3
praise owner
2 collected complaint signal(s) missing feature support 2 source links Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security headers lockouts, bot/spam defenses, risky access changes, and incident alerts
CSP Friendly Security praise owner · intel 46.5 · weakness 28.1
praise owner
4 collected complaint signal(s) bugs support 2 source links Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security headers lockouts, bot/spam defenses, risky access changes, and incident alerts

Repeated Themes

0 shown

No repeated plugin-level themes have been generated yet.

Collected Signals

20 shown from 35 collected
complaint Concerns about nginx deployment support · 2026-05-20T20:50:14+00:00 · high severity · content security policy

Concerns about nginx deployment: users show bugs, support, setup pain that may indicate a product gap.

Evidence: Kudos to you for trying to resolve an issue that should really be of top concern to the entire WordPress ecosystem!
bugs support setup trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
complaint Need to View/Copy Generated CSP support · 2026-03-24T19:53:54+00:00 · medium severity · content security policy

Need to View/Copy Generated CSP: users show support, setup pain that may indicate a product gap.

Evidence: Need to View/Copy Generated CSP I am a low skilled user seeking to make my site (sturbridgecapital.com) compliant with expectations of external scanners such as internet.nl which push me to have a very strict CSP.
support setup api trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
complaint Problem with upgrade to 1.3.0 support · 2026-03-12T20:21:56+00:00 · medium severity · content security policy

Problem with upgrade to 1.3.0: users show bugs, compatibility, setup pain that may indicate a product gap.

Evidence: Operating System: Linux Web Server: Apache WordPress Version: 6.9.4 PHP Version: 8.5.2 No unsafe-inline Version: 1.3.0 libxml Version: 20914 PHP extensions: +———–+———-+———–+ | extension | version | status | +———–+———-+———–+ | ctype | 8.5.2 | installed | | date | 8.5.2 | installed | | dom | 20031129 | installed | | filter | 8.5.2 | installed | | hash | 8.5.2
bugs compatibility setup trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
complaint Google youTube, reCaptcha integrity failure support · 2026-03-04T02:53:49+00:00 · high severity · content security policy

Google youTube, reCaptcha integrity failure: users show security, bugs, support pain that may indicate a product gap.

Evidence: Google youTube, reCaptcha integrity failure reCaptcha error Failed to find a valid digest in the ‘integrity’ attribute for resource ‘ https://www.google.com/recaptcha/api.js?hl=en&ver=6.9.1#038;render=explicit’ ; with computed SHA-256 integrity ‘k14ryYrM1KYcKsCdkuqoQDoGn480m4fP1lZEZmaICo8=’.
security bugs support api trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
complaint How to add other headers to the CSP support · 2026-03-04T02:07:27+00:00 · high severity · content security policy

How to add other headers to the CSP: users show security, missing feature pain that may indicate a product gap.

Evidence: How to add other headers to the CSP When I do a test I noticed that security headers sees the CSP but not the other type of headers i.e.
security missing feature trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
mixed SHA256 not loading support · 2025-12-09T03:11:25+00:00 · medium severity · content security policy

SHA256 not loading: users show bugs, missing feature, support pain that may indicate a product gap.

Evidence: I am not sure if I have a plugin problem or a cache issue.
bugs missing feature support setup trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
mixed Activating the plugin does nothing support · 2025-09-12T11:34:11+00:00 · medium severity · content security policy

Activating the plugin does nothing: users show bugs, compatibility, performance pain that may indicate a product gap.

Evidence: Also I have noticed that enabling the plugin does not create any tables in the database, I don’t know if this is normal.
bugs compatibility performance support trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
complaint Fatal error after upgrading to v1.2.3 support · 2025-08-11T12:58:15+00:00 · high severity · content security policy

Fatal error after upgrading to v1.2.3: users show bugs, compatibility, migration pain that may indicate a product gap.

Evidence: Fatal error after upgrading to v1.2.3 Hi, Following an update to v1.2.3, my sites are down with the following error : Fatal error: Uncaught TypeError: Cannot assign __PHP_Incomplete_Class to property Rubix\ML\Classifiers\KNearestNeighbors::$kernel of type Rubix\ML\Kernels\Distance\Distance in F:\apps\www.test.com\wp-content\plugins\no-unsafe-inline\vendor\ru
bugs compatibility migration easy trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
complaint Fatal error when activating the plugin. support · 2025-07-22T14:04:27+00:00 · high severity · content security policy

Fatal error when activating the plugin.: users show bugs, compatibility pain that may indicate a product gap.

Evidence: Fatal error when activating the plugin.
bugs compatibility trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
complaint Problem with recaptcha during capture phase support · 2025-07-16T12:53:59+00:00 · high severity · content security policy

Problem with recaptcha during capture phase: users show security, bugs pain that may indicate a product gap.

Evidence: Problem with recaptcha during capture phase Hi, I have just started the capture phase.
security bugs trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
complaint Cookie Banner Not Displaying When Test CSP Policy is Enabled (No Errors Logged) support · 2025-07-14T16:13:23+00:00 · medium severity · content security policy

Cookie Banner Not Displaying When Test CSP Policy is Enabled (No Errors Logged): users show bugs, support pain that may indicate a product gap.

Evidence: Cookie Banner Not Displaying When Test CSP Policy is Enabled (No Errors Logged) I’m having trouble with the Enzuzo cookie consent banner on my site.
bugs support trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
mixed TrustedHTML throws an error in no-unsafe-inline-fix-style.js support · 2025-06-20T01:24:14+00:00 · high severity · content security policy

TrustedHTML throws an error in no-unsafe-inline-fix-style.js: users show security, bugs, compatibility pain that may indicate a product gap.

Evidence: TrustedHTML throws an error in no-unsafe-inline-fix-style.js One of my plugins is loading reCAPTCHA, which is throwing an e.replace is not a function error in the no-unsafe-inline-fix-style.min.js script, relating to reCAPTCHA trying to add its badge HTML.
security bugs compatibility missing feature trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
complaint External & inline always “no items” found support · 2025-04-25T10:32:39+00:00 · medium severity · content security policy

External & inline always “no items” found: users show bugs, missing feature, support pain that may indicate a product gap.

Evidence: Is there anything I might be missing or any known issues that could prevent the plugin from detecting the inline scripts and external sources?
bugs missing feature support trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
mixed Error support · 2025-04-25T03:26:15+00:00 · high severity · content security policy

Error: users show bugs, compatibility, support pain that may indicate a product gap.

Evidence: Error When I enable tag capture, I get the following error: Fatal error: Uncaught Rubix\ML\Exceptions\RuntimeException: Estimator has not been trained.
bugs compatibility support value trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
complaint Enabled report-only mode, but nothing happened support · 2025-03-21T15:40:51+00:00 · medium severity · content security policy

Enabled report-only mode, but nothing happened: users show setup pain that may indicate a product gap.

Evidence: But after I installed it to live site – nothing basically happened after I activated it with read-only mode.
setup cache trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
complaint CSP Blocks no-unsafe-inline-fix-style.min.js support · 2025-03-06T07:55:56+00:00 · high severity · content security policy

CSP Blocks no-unsafe-inline-fix-style.min.js: users show security, bugs, support pain that may indicate a product gap.

Evidence: CSP Blocks no-unsafe-inline-fix-style.min.js Hi, First of all, thank you for this plugin, it has helped us easily manage the CSP headers.
security bugs support trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
complaint CSP Issue in WordPress with No Unsafe Inline Plugin & .htaccess support · 2025-02-26T21:44:38+00:00 · high severity · content security policy

CSP Issue in WordPress with No Unsafe Inline Plugin & .htaccess: users show security, bugs, compatibility pain that may indicate a product gap.

Evidence: CSP Issue in WordPress with No Unsafe Inline Plugin & .htaccess Hello everyone, I’m experiencing an issue with Content Security Policy (CSP) in WordPress while using the No Unsafe Inline plugin.
security bugs compatibility performance trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
complaint Compatibility with caching & JS/CSS optimization plugins support · 2025-01-29T14:35:56+00:00 · high severity · content security policy

Compatibility with caching & JS/CSS optimization plugins: users show security, bugs, compatibility pain that may indicate a product gap.

Evidence: Compatibility with caching & JS/CSS optimization plugins Hi, I’m wondering if some caching & JS/CSS optimization plugins are known to work when “No unsafe-inline” plugin is enabled?
security bugs compatibility missing feature trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
neutral disable style-src nonce support · 2025-01-14T14:03:23+00:00 · medium severity · content security policy

disable style-src nonce: neutral conversation with limited structured signal.

Evidence: disable style-src nonce I cannot seem to disable style-src nonce even though it’s set to none (it was set to nonce). This topic was modified 1 year, 4 months ago by fuzzy21 . I cannot seem to disable style-src nonce even though it’s set to none (it was set to nonce). This topic was modified 1 year, 4 months ago by fuzzy21 .
trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
neutral cannot disable noncing support · 2025-01-07T13:56:19+00:00 · medium severity · content security policy

cannot disable noncing: users show bugs, setup pain that may indicate a product gap.

Evidence: We have a lot of base rules we setup.
bugs setup trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions