unsafe-inline in your CSP basically turns off XSS protection. Here's how to get rid of it using nonces, hashes, or by refactoring your code.
We scan thousands of CSP headers. These are the mistakes that come up over and over — and they're all fixable.