@sheogorath
By the way, the next level after CSP is the Trusted Policy which I have just recently rolled out:
https://webcookies.org/articles/88/practical-trusted-types-implementation