This page uses HTTPS-only assets. A Content Security Policy with
upgrade-insecure-requests coerces any stray http:// references to HTTPS.
CSP: upgrade-insecure-requests
Why it’s good: if a developer accidentally uses http:// for a script that is
available over HTTPS, CSP upgrades it automatically, preserving integrity.
jQuery is available to confirm execution.We load an image over HTTPS to avoid mixed content entirely.
https://www.badssl.com/favicon.ico.