WPIntell

csp-manager

Content Security Policy Manager

Plugin for configuring Content Security Policy headers for your site. Allows different CSP headers for admin, logged inn frontend and regular visitors

2.0K
34.9K
4.3
0
7
6

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

52 / 76 rows with source links

68.4% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

24 rows with no attached evidence

0 rows have source counts but still need direct links.

Download Momentum

180 days
284 248 14.5% 1.8K

Source Evidence

Open evidence explorer
complaint support · high severity · relevance 1.0
how to fill sites

how to fill sites: users show security, bugs, support pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
how to fill sites I’m on the report only, had lists of errors from Sentry, but how do I fill the sites in the box?
complaint support · high severity · relevance 0.91
Customize not working. This content is blocked. Contact the site owner to fix th

Customize not working. This content is blocked. Contact the site owner to fix th: users show security, bugs, support pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
Contact the site owner to fix the issue.” I have CSP Manager Admin policy to Disabled.
mixed support · high severity · relevance 0.89
CSP in Firefox

CSP in Firefox: users show security, bugs, missing feature pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
CSP in Firefox In Firefox, I’m getting an error of Content Security Policy: The page’s settings blocked the loading of a resource at https://morgridge.org/news/page/2/ (“default-src”).
complaint support · medium severity · relevance 0.87
Plugin not activating

Plugin not activating: users show bugs, compatibility, missing feature pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
my php version is – 7.2 and I have updated my PHP version to 7.4 and my WordPress Version is 5.9.
mixed support · medium severity · relevance 0.85
Can’t get it working at all

Can’t get it working at all: users show bugs, performance, missing feature pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
Viewing source, clearing/bypassing cache I don’t see anything CSP added to the source.
complaint support · medium severity · relevance 0.75
Problems with caching

Problems with caching: users show bugs, compatibility pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
I think the plugin works fine.
mixed support · medium severity · relevance 0.72
no CSP for unlogged visitors

no CSP for unlogged visitors: users show bugs, support pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
Any help would be appreciated Mat Hi there, it’s quite strange but I don’t have any CSP setted in the headers when I’m not logged in.
complaint support · medium severity · relevance 0.69
CSP Manager doesn’t seem to be working

CSP Manager doesn’t seem to be working: users show support pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
The page I need help with: [ log in to see the link] I’m trying to add a CSP rule to enable embedding content from player.streamguys.com in an iframe.
complaint support · medium severity · relevance 0.69
Adding nonce to rules

Adding nonce to rules: users show support pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
Adding nonce to rules Hi, does the plugin support using nonce ?
mixed support · medium severity · relevance 0.66
CSP For ‘Require Trusted Types’

CSP For ‘Require Trusted Types’: users show support pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
The currently supported directives were chosen based on what I had a need for myself, but it makes sense to expand upon this.

Competitor Context

6 shown
Cookies and Content Security Policy praise owner · intel 66.7 · weakness 49.0
praise owner
1 unresolved support thread(s) 7 collected complaint signal(s) security compatibility 2 source links Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and compliance-sensitive marketing teams · Wedge: audit GDPR consent state, tracking disclosures, cookie behavior, and compliance drift
GD Security Headers praise owner · intel 63.4 · weakness 47.0
praise owner
16 collected complaint signal(s) missing feature security 2 source links Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
No unsafe-inline praise owner · intel 62.0 · weakness 46.0
praise owner
1 unresolved support thread(s) 18 collected complaint signal(s) bugs security 2 source links Proof Blocked Evidence linked to opportunity
Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
Security Header Generator praise owner · intel 47.9 · weakness 24.7
praise owner
2 collected complaint signal(s) security bugs 2 source links Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
HTTP Security Header praise owner · intel 45.4 · weakness 22.3
praise owner
2 collected complaint signal(s) missing feature support 2 source links Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security headers lockouts, bot/spam defenses, risky access changes, and incident alerts
CSP Friendly Security praise owner · intel 44.7 · weakness 28.1
praise owner
4 collected complaint signal(s) bugs support 2 source links Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security headers lockouts, bot/spam defenses, risky access changes, and incident alerts

Repeated Themes

0 shown

No repeated plugin-level themes have been generated yet.

Collected Signals

19 shown from 19 collected
question Plugin Support and Updates support · 2025-07-21T13:00:14+00:00 · low severity · content security policy

A user asks whether the Content Security Policy Manager plugin is still supported after three years without updates and receives no answer.

Evidence: As it hasn’t had an update for 3 years I wanted to check.
support plugin maintenance trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint Customize not working. This content is blocked. Contact the site owner to fix th support · 2024-03-07T17:30:48+00:00 · high severity · content security policy

Customize not working. This content is blocked. Contact the site owner to fix th: users show security, bugs, support pain that may indicate a product gap.

Evidence: Contact the site owner to fix the issue.” I have CSP Manager Admin policy to Disabled.
security bugs support form trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
praise Report To not working (5 stars) review · 2023-07-13T00:19:16+00:00 · medium severity · content security policy

Report To not working: users show missing feature, support pain that may indicate a product gap.

Evidence: My CSP settings are as follows: In Policy: report-to filed, I filled in csp-endpoint , in Frontend Policy Report-To Header field, I filled in the following JSON data { "group": "csp-endpoint", "max_age": 10886400, "endpoints": [ { "url": "{CSP REPORT ENDPOINT}" } ] } After saving changes in the CMS, all the commas disappeared in Frontend Policy Report-To Hea
missing feature support trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint kills all CSS styles (1 star) review · 2023-02-18T14:46:25+00:00 · medium severity · content security policy

kills all CSS styles: complaint conversation with limited structured signal.

Evidence: kills all CSS styles As soon as I leave the backend the view of my side is without any CSS. Only the plain HTML. As soon as I leave the backend the view of my side is without any CSS. Only the plain HTML.
trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
praise Very helpful and useful plugin. do you provide filters ? (5 stars) review · 2023-01-25T09:20:32+00:00 · medium severity · content security policy

Very helpful and useful plugin. do you provide filters ?: users show support pain that may indicate a product gap.

Evidence: Very helpful and useful plugin.
support trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
praise Examples per directives? support · 2023-01-04T19:58:23+00:00 · medium severity · content security policy

Examples per directives?: users praise quality, which suggests what competitors already do well.

Evidence: That would be a very welcome addition, other than that excellent plugin 🙂 That would be a very welcome addition, other than that excellent plugin 🙂
quality trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint CSP Manager doesn’t seem to be working support · 2022-05-05T00:15:42+00:00 · medium severity · content security policy

CSP Manager doesn’t seem to be working: users show support pain that may indicate a product gap.

Evidence: The page I need help with: [ log in to see the link] I’m trying to add a CSP rule to enable embedding content from player.streamguys.com in an iframe.
support trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
praise I like all the options for logged-in versus anonymous and report-only (5 stars) review · 2022-04-10T15:14:30+00:00 · medium severity · content security policy

I like all the options for logged-in versus anonymous and report-only: users show missing feature, support, setup pain that may indicate a product gap.

Evidence: I like all the options for logged-in versus anonymous and report-only This plugin is well thought out and does what I need it to.
missing feature support setup reliable trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint Plugin not activating support · 2022-02-16T14:23:27+00:00 · medium severity · content security policy

Plugin not activating: users show bugs, compatibility, missing feature pain that may indicate a product gap.

Evidence: my php version is – 7.2 and I have updated my PHP version to 7.4 and my WordPress Version is 5.9.
bugs compatibility missing feature support trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint Adding nonce to rules support · 2021-11-07T09:19:06+00:00 · medium severity · content security policy

Adding nonce to rules: users show support pain that may indicate a product gap.

Evidence: Adding nonce to rules Hi, does the plugin support using nonce ?
support trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
praise Extraordinaire ! (5 stars) review · 2021-11-01T09:02:26+00:00 · medium severity · content security policy

Extraordinaire !: praise conversation with limited structured signal.

Evidence: Extraordinaire ! Ce plugin m;a fait gagner des heures de travail. Ce plugin m;a fait gagner des heures de travail.
trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint Problems with caching support · 2021-10-28T18:15:21+00:00 · medium severity · content security policy

Problems with caching: users show bugs, compatibility pain that may indicate a product gap.

Evidence: I think the plugin works fine.
bugs compatibility reliable value trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
mixed no CSP for unlogged visitors support · 2021-09-07T23:52:58+00:00 · medium severity · content security policy

no CSP for unlogged visitors: users show bugs, support pain that may indicate a product gap.

Evidence: Any help would be appreciated Mat Hi there, it’s quite strange but I don’t have any CSP setted in the headers when I’m not logged in.
bugs support quality trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
mixed Can’t get it working at all support · 2021-07-27T19:00:32+00:00 · medium severity · content security policy

Can’t get it working at all: users show bugs, performance, missing feature pain that may indicate a product gap.

Evidence: Viewing source, clearing/bypassing cache I don’t see anything CSP added to the source.
bugs performance missing feature support trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
praise Great plugin to manage CSP (5 stars) review · 2021-05-14T14:01:12+00:00 · medium severity · content security policy

Great plugin to manage CSP: users praise quality, which suggests what competitors already do well.

Evidence: Great plugin to manage CSP Great plugin, thank you.
quality trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint how to fill sites support · 2021-04-27T07:12:22+00:00 · high severity · content security policy

how to fill sites: users show security, bugs, support pain that may indicate a product gap.

Evidence: how to fill sites I’m on the report only, had lists of errors from Sentry, but how do I fill the sites in the box?
security bugs support setup trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
mixed CSP in Firefox support · 2021-02-09T17:20:06+00:00 · high severity · content security policy

CSP in Firefox: users show security, bugs, missing feature pain that may indicate a product gap.

Evidence: CSP in Firefox In Firefox, I’m getting an error of Content Security Policy: The page’s settings blocked the loading of a resource at https://morgridge.org/news/page/2/ (“default-src”).
security bugs missing feature support trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
mixed Add frame-ancestors Policy support · 2020-12-19T01:13:12+00:00 · low severity · content security policy

Add frame-ancestors Policy: users show support pain that may indicate a product gap.

Evidence: The currently supported directives were chosen based on what I had a need for myself, but it makes sense to expand upon this.
support trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
mixed CSP For ‘Require Trusted Types’ support · 2020-10-13T17:23:02+00:00 · medium severity · content security policy

CSP For ‘Require Trusted Types’: users show support pain that may indicate a product gap.

Evidence: The currently supported directives were chosen based on what I had a need for myself, but it makes sense to expand upon this.
support trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts