• Hi, Giuseppe! Kudos to you for trying to resolve an issue that should really be of top concern to the entire WordPress ecosystem!

    I’d like to install “No unsafe inline”, but I am concerned about whether it will work for my specific case.

    My site of concern is hosted on an Ngnix server (Dreamhost’s DreamPress service).

    According to Dreamhost Support, since Ngnix does not allow directory-level config files (that I could modify myself), the only way to modify the CSP is to submit a support request to Dreamhost technical staff and wait for them to deploy it!

    This sounds like a big bottleneck, particularly in the early stages. And it seems like the CSP will need to be constantly updated every time a plugin updates or an author adds inline JS or CSS to a page.

    And then I found this unresolved support query from November 2024:
    https://ww.wp.xz.cn/support/topic/activating-report-only-mode-crashes-website-on-nginx/

    Do you have more recent insight on nginx compatibility?

You must be logged in to reply to this topic.