Content Security Policy (CSP) has been in support by most modern browsers for a while now. The RFC of the first version was released in 2012. More than 10 years later, and with Level 3 as Working Draft in 2023, a far-reaching study of CSP deployment across the Internet was due. The top one million most popular sites were scanned and their CSP related headers were stored. The values of the CSP headers were analyzed to answer several questions. How popular is this security measure nowadays? What are common pitfalls and misconfigurations within CSP headers? How often do sites enable reporting of violations to take a more proactive approach? Do sites blindly trust third parties such as content delivery networks and how can this trust be abused? This talk will cover the results of the analysis against real world data. Additionally, it will present new and not so popular techniques to bypass CSP by abusing third-party trust. Finally, we will propose effective hardening and mitigation to these weaknesses.