Plugin categories

Create a Website with AI
Content Security Policy Pro

Content Security Policy Pro

This Content Security Policy plugin will help the setup the Content-Security-Policy HTTP response header and block the XSS vulnerabilities.

5

Rating summary

0

Reviews

400

Active installations

Content Security Policy Pro
Content Security Policy Pro
Content Security Policy Pro
Content Security Policy Pro

Overview

Compatibility

Installation instructions

Customer support & learning resources

Changelog

Main benefits

Blocks XSS vulnerabilities

Specifies approved content sources

Delivered via HTTP header

Widely supported and deployed

Effective XSS countermeasure

About this plugin

Author: thapa.laxman
Categories: Security
Version: 1.3.5
Last updated: 04-04-2019
WordPress version: 3.0.1
Tested up to: 5.1.19
PHP version required: false
Languages:

Overview

The Content Security Policy (CSP) Wordpress plugin serves as a crucial security measure by allowing website administrators to send CSP headers, which inform browsers of the sources from which content can be safely loaded and which should be blocked. By specifying a whitelist of approved sources, this plugin effectively counteracts Cross Site Scripting (XSS) vulnerabilities, enhancing the security of web applications. The plugin supports various CSP directives, such as default-src for general content, script-src for executable scripts, img-src for images, and many others for different types of media and resources. Created by Laxman Thapa, this tool simplifies the deployment of CSP through HTTP response headers, providing a straightforward and widely supported solution for bolstering browser security.

Enhanced Security

  • Blocks XSS vulnerabilities by controlling what the browser can execute.
  • Allows specifying a whitelist of approved sources for content loading.
  • Acts as an effective countermeasure for Cross Site Scripting (XSS) attacks.

Flexible Content Loading Policies

  • Defines loading policies for various resource types such as scripts, styles, images, and media.
  • Supports multiple directives like script-src, style-src, img-src, and more to fine-tune content loading.
  • Fallback policies can be set using default-src directive.

Easy Deployment

  • Delivered via HTTP response header, similar to HSTS.
  • Widely supported across different browsers.
  • Usually easy to deploy on existing websites.

Detailed Control and Reporting

  • Supports directives like script-nonce and plugin-types for granular control over script execution and plugin usage.
  • Allows specifying URIs for form actions and script interfaces.
  • Provides a report-uri directive for sending reports about policy violations.

Features list

Feature

Premium version

130 Prebuilt Websites

Access to 130 ready-to-use website templates.

Built-in AMP for WooCommerce

Accelerated Mobile Pages support for WooCommerce.

High converting eCommerce features

Tools designed to boost eCommerce conversion rates.

Fake live viewing

Simulates live viewing to create urgency.

Product variation swatches

Visual representation of product variations.

Fake sale popup

Displays fake sales notifications to encourage purchases.

Request a quote

Allows customers to request price quotes.

Product sold counter

Shows the number of products sold to build trust.

Frequently bought together

Suggests products often purchased together.

Cross-sells after 'Add to Cart'

Recommends additional products after adding to cart.

Sticky add to cart bar

Persistent add to cart bar for easy access.

Free shipping progress bar on Cart page

Displays progress towards free shipping eligibility.

Product with video

Allows embedding videos in product pages.

Shopping cart countdown

Countdown timer to encourage quick checkout.

Sale countdown timer

Displays a countdown for ongoing sales.

Pricing

XStore

$39 / one-time

Plan includes

130 Prebuilt Websites
Built-in AMP for WooCommerce
High converting eCommerce features
Fake live viewing
Product variation swatches
Fake sale popup
Request a quote
Product sold counter
Buy Now

In some cases companies have different prices based on various components like a location. As a result the prices displayed here can differ from the ones you see on their websites.

See all pricing options

Rating and reviews

5

Rating summary

0

Reviews

400

Active installations

5
4
3
2
1

FAQ

I am confused with all the settings. What settings should I use?

What is Content Security Policy (CSP)?

How is CSP delivered?

What are some common CSP directives?

How does CSP help in blocking XSS vulnerabilities?

Who wrote this plugin?

What is the 'default-src' directive?

What does the 'script-src' directive do?