CSP Header: default-src 'self' 'unsafe-inline' 'unsafe-eval' *
Description: Weak CSP - allows inline scripts and eval
Try loading external JavaScript: