Implement a strict CSP to prevent xss attacks

The site I am inquiring about is limestoneholeyrock.com

I have 2 error messages in Lighthouse

  1. Script-src directive is missing

  2. Object-src is missing

I am hoping to find either a step by step guide that I can follow to do this, find out if there is an app or service I can buy that will manage this issue or mot preferably, get someone here in Shopify Community who will do the job for me.

Thank you very much!