GrootMadeGrootMade
Pricing
GrootConnectRegister
Explore allThemesPluginsKitsCollectionsPacksAuthorsCategoriesTagsTrendingDownload PluginPricingResourcesBlogChangelogContact usDocumentationCommunity
GrootMadeGrootMade
ExplorePricingDashboardBlogContact usTermsPrivacy

The WP® trademark is the intellectual property of the WP Foundation, and the Woo® and WooCommerce® trademarks are the intellectual property of WooCommerce, Inc. Uses of the WP®, Woo®, and WooCommerce® names in this website are for identification purposes only and do not imply an endorsement by WP Foundation or WooCommerce, Inc. GrootMade is not endorsed or owned by, or affiliated with, the WP Foundation or WooCommerce, Inc.

Petra

AI assistant for GrootMade

Hi! I'm Petra 👋 Ask me to help you find the perfect WP plugin, theme, or template kit.

Need human help?
Join our DiscordChat on Telegram
Join Discord
ExploreStrict CSP

Strict CSP

Blocks XSS attacks with strict content security policy.

Enforces a Strict Content Security Policy on the frontend and login screen to mitigate XSS vulnerabilities. Requires scripts to use WordPress APIs for execution.

Visit Strict CSP
fv_plugin

Strict CSP

Blocks XSS attacks with strict content security policy.

Visit site

This plugin protects your site from cross-site scripting (XSS) attacks by enforcing a Strict Content Security Policy (CSP) on the frontend and login screen. It is designed for site owners and developers who want to harden their site against script injection without breaking legitimate functionality.

  • Nonce-based script execution: The plugin assigns a unique cryptographic nonce to every allowed script. Only scripts with the correct nonce will execute, blocking unauthorized inline scripts and event handlers like onclick or onload.
  • Automatic embed support: Scripts added by embeds (e.g., Tweets) automatically receive the nonce attribute, ensuring third-party content remains functional under the policy.
  • Admin area exclusion: The policy is not applied to the WordPress Admin, preventing compatibility issues with admin plugins that may not use the required script APIs.
  • Developer guidance: The plugin encourages best practices by requiring themes and plugins to use WordPress functions like wp_print_inline_script_tag() or wp_enqueue_script() instead of directly printing <script> tags. Scripts that bypass these APIs will be blocked and logged in the browser console.
  • Compatibility with modern WordPress: Tested up to WordPress 6.9, the plugin leverages core improvements that eliminated manual script tag construction, making Strict CSP feasible for most sites.

Package Contents

Package contents information is not available yet.

Version History

No version history available for this item yet.

Comments

No comments yet. Be the first to start the conversation!

Security Scan

More themes and plugins like Strict CSP

About

Enforces a Strict Content Security Policy on the frontend and login screen to mitigate XSS vulnerabilities. Requires scripts to use WordPress APIs for execution.

  • Strict CSP
  • v0.3.2
  • 5 days ago
  • Apr 25, 2026
  • Access: Silver
  • Weston Ruter
  • Plugin
  • 0
  • No comments