CSP is the third solution I showed because it’s a powerful extra layer: you can control what scripts are allowed to run at all. I used it to block inline script execution so the injected code stayed in the HTML but couldn’t execute.
You'll be taken to Developer to complete your purchase.