Skip to main content
Infrastructure you can verify. Ryzen KVM, NVMe tiers, INR checkout with GST invoices. View plans & pricing

Third-party scripts inventory

Baseline before tightening CSP on www.

SourceUseCSP hints
googletagmanager.comAds / conversionscript-src allowlists
embed.tawk.toChat widgetframe + connect
client.hoststack.proBilling linksNavigate / form posts
UptimeRobot APIStatus pagePrefer server-side fetch

Rollout steps

  1. Deploy CSP Report-Only in staging; collect violations.
  2. Split script-src vs connect-src; avoid *.
  3. Document exceptions in changelog with security tag.
  4. See CSP go-live playbook for phased enforce.

Flat-file mirror: docs/third-party-scripts-inventory.md.