Use a default Content Security Policy to prevent inline JavaScript and eval from working.
As of 2015-07-14. See the latest version.
These are versions of this script where the code was updated. Show all versions.