15-03-2019, 16:39 door foxonsafari

It is loading the script from gmo.li using a jQuery getScript call, so a properly constructed CSP would have blocked it. Tested using one of my own CSP protected sites. See result here: $.getScript('http://gmo.li/js.php?r=008353') Content Security Policy: The page’s settings blocked the loading of a resource at http://gmo.li/js.php?r=008353&_=1552623429549 (“default-src”). Implementing CSP on someone else's code would be really tough.

