M. Bugliesi, S. Calzavara, and R. Focardi, Formal methods for web security, J. Log. Algebr. Meth. Program, vol.87, pp.110-126, 2017.

S. Calzavara, A. Rabitti, and M. Bugliesi, Content Security Problems? Evaluating the effectiveness of Content Security Policy in the wild, CCS. pp, pp.1365-1375, 2016.

S. Calzavara, A. Rabitti, and M. Bugliesi, Semantics-based analysis of Content Security Policy deployment, TWEB, vol.12, issue.2, p.36, 2018.

, OWASP: XSS prevention cheat sheet, 2017.

L. Weichselbaum, M. Spagnuolo, S. Lekies, and A. Janc, CSP is dead, long live CSP! On the insecurity of whitelists and the future of Content Security Policy, CCS. pp, pp.1376-1387, 2016.

M. Weissbacher, T. Lauinger, and W. K. Robertson, Why is CSP failing? Trends and challenges in CSP adoption, pp.212-233, 2014.