Free

Content Security Policy Demo

Frontend scripts and styles are written to run under a strict Content-Security-Policy. No eval, no inline event handlers, no remote script CDNs.

What it does

LandTech Extras widgets load their JavaScript and CSS from files on your site. A host can send a strict Content-Security-Policy without breaking tabs, shares, or galleries from this plugin. Elementor and your theme ship their own scripts — this page covers LandTech Extras only.

Example header you can add on staging:

default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'

  • Works with free Elementor
  • No Elementor Pro required
  • Copy the live setup

Live demo

What LandTech Extras does so a strict CSP can stay on:

  • No onclick, onmouseover, or other inline event attributes.
  • No javascript: links.
  • No eval() or new Function() in plugin scripts.
  • Clicks use data-ltxe-action and a single delegated listener.
  • Widget styles live in stylesheets or CSSOM — not HTML style="" on controls.

Click the tabs and share buttons below. They should work on this page without loading a third-party script CDN.

Tabs (keyboard + click)

This tab switch is handled by the plugin’s tabs script. The markup has no onclick attributes.

Share buttons (no third-party pixels)

How to implement

  1. Use the tabs and share buttons in the live demo — they run from plugin files, not inline onclick handlers.
  2. On your own host, add a CSP header that blocks eval() and remote scripts.
  3. Open this page (or Tabs, Gallery, Testimonials) and check the browser console for CSP violations from LandTech Extras files.
  4. Ignore reports from Elementor or the theme unless you control those assets too.