function tg_enable_strict_transport_security_hsts_header_wordpress() { header( "Content-Security-Policy: default-src * data: 'unsafe-eval'; script-src * data: 'unsafe-inline' 'unsafe-eval' *; connect-src *; img-src * data:; style-src * 'unsafe-inline';base-uri *;form-action *" ); } add_action( 'send_headers', 'tg_enable_strict_transport_security_hsts_header_wordpress' );