Content Security Policy

Author
KD Web
Version
0.0.6
Requires
6.0.0
Tested
6.9.9
Requires PHP
8.0.0

Builds and sends a nonce-based Content-Security-Policy header, with an admin builder covering every CSP directive, sensible defaults so themes/plugins/embeds keep working, and full compatibility with LiteSpeed Cache.

Features

How to Use

  1. Install and activate the plugin.
  2. Go to Settings → CSP in the WordPress admin dashboard.
  3. Start in Report-Only mode, then review the Integrations tab for the third-party services your site actually uses.
  4. Check your browser console for CSP violation reports, adjust directives on the Directive Builder tab as needed, then switch off Report-Only to start enforcing.

Benefits

Changelog

0.0.6

0.0.5

0.0.4

0.0.3

0.0.2

0.0.1

Released

Download

Back