diff --git a/web/index.html b/web/index.html
index 87fa1f13d..bd5c75382 100644
--- a/web/index.html
+++ b/web/index.html
@@ -8,7 +8,7 @@
+ content="script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://static.hotjar.com https://script.hotjar.com https://www.dropbox.com https://apis.google.com https://accounts.google.com; worker-src 'self' blob:; object-src 'none'; base-uri 'self';">