Allowing users to supply a
nonce
option which is then added to the generated <script> tag would enable this preset to be used with a Content Security Policy, but without demanding
script src unsafe-inline
, which would be undesirable.