Stripe fucking glows in the dark.
> Include the Stripe.js script on each page of your site—it should always be loaded directly from
https://js.stripe.com, rather than included in a bundle or hosted yourself.
>
> To best leverage Stripe’s advanced fraud functionality, include this script on every page, not just the checkout page. This allows Stripe to detect suspicious behavior that may be indicative of fraud as customers browse your website.
and
> Note: To be PCI compliant, you must load Stripe.js directly from
https://js.stripe.com. You cannot include it in a bundle or host it yourself. This package wraps the global Stripe function provided by the Stripe.js script as an ES module.
and
> connect-src,
https://api.stripe.com,
https://maps.googleapis.com...
> script-src,
https://js.stripe.com,
https://maps.googleapis.comEven more reasons to encourage crypto over fiat...