Third-Party Integrations

A few lines of vendor markup give your site comments, maps, video, bot checks, payments and analytics. Each embed also runs someone else's code on your page and may set cookies before the visitor agrees. Load vendor scripts async, isolate what you can in iframes (<iframe> and Sandboxing and Trusted Types), list vendor origins in your Content Security Policy (Content Security Policy), and hold back anything that tracks until the visitor consents (Analytics and Consent).

Subsections