WPIntell

sea-sp-community-edition

SeaSP Community Edition

SeaSP Community Edition is an automated Content Security Policy Manager. SeaSP allows you to create, configure, manage, and deploy a Content Security …

10
4.4K
4.7
0
3
5

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

53 / 85 rows with source links

62.4% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

32 rows with no attached evidence

0 rows have source counts but still need direct links.

Download Momentum

180 days
28 50 -44.0% 278

Source Evidence

Open evidence explorer
complaint support · high severity · relevance 1.0
Objects blocked but no clear error message in browser console

Objects blocked but no clear error message in browser console: users show security, bugs, compatibility pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
Objects blocked but no clear error message in browser console After updating the plugin to ver 1.5.0 certain elements on a page are being blocked (when the CSP is active), but no error message in displayed in the browser console explaining what directive is concerned.
complaint support · high severity · relevance 1.0
Interpretation of browser error msg when the script is from 3rd party site.

Interpretation of browser error msg when the script is from 3rd party site.: users show security, bugs, missing feature pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
Interpretation of browser error msg when the script is from 3rd party site.
mixed support · high severity · relevance 0.95
Redundant directive values redux

Redundant directive values redux: users show security, bugs, performance pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
Redundant directive values redux After doing a fresh install of ver.
mixed support · high severity · relevance 0.95
WP-Admin access

WP-Admin access: users show security, bugs, compatibility pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
WP-Admin access I have SeaSP set in Report Only and Error Correction on.
mixed support · high severity · relevance 0.89
Current violations gathering

Current violations gathering: users show security, bugs, performance pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
I intend to run with Error Collection On for a reasonable time (weeks).
mixed support · high severity · relevance 0.89
Great job!

Great job!: users show security, missing feature, pricing pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
Great job!
praise review · high severity · relevance 0.73
Interface makes it easier for beginners

Interface makes it easier for beginners: users show security, missing feature, pricing pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
Interface makes it easier for beginners After my initial failed install (see support thread) and subsequent support I came back for a second try with this as an updated version was available.
praise review · high severity · relevance 0.66
One of the best security content protector

One of the best security content protector: users show security, missing feature, support pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
One of the best security content protector Best plugin when it comes to protecting and managing your content and it also collects the data of you site which violates certain things to help you to find and correct as soon as possible.it also auto mates mail processing making it easier for the user to manage…It also packed up with some ton of awesome feature i
mixed support · medium severity · relevance 0.85
fails to load bootstrap

fails to load bootstrap: users show bugs, compatibility, missing feature pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
fails to load bootstrap Installed twice.
mixed support · medium severity · relevance 0.84
Use DB prefix when dropping tables

Use DB prefix when dropping tables: users show bugs, compatibility, performance pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
Use DB prefix when dropping tables Please do not forget to use the local DB prefix in the commands to drop database tables.

Competitor Context

7 shown
Content Security Policy Manager praise owner · intel 69.5 · weakness 57.3
praise owner
stale update history 6 collected complaint signal(s) support bugs 2 source links Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Cookies and Content Security Policy praise owner · intel 66.7 · weakness 49.0
praise owner
1 unresolved support thread(s) 7 collected complaint signal(s) security compatibility 2 source links Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and compliance-sensitive marketing teams · Wedge: audit GDPR consent state, tracking disclosures, cookie behavior, and compliance drift
GD Security Headers praise owner · intel 63.4 · weakness 47.0
praise owner
16 collected complaint signal(s) missing feature security 2 source links Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
No unsafe-inline praise owner · intel 62.0 · weakness 46.0
praise owner
1 unresolved support thread(s) 18 collected complaint signal(s) bugs security 2 source links Proof Blocked Evidence linked to opportunity
Buyer: agencies, multisite operators, and maintenance teams · Wedge: surface multisite update risk, network drift, reporting gaps, and client-site exceptions
Security Header Generator praise owner · intel 47.9 · weakness 24.7
praise owner
2 collected complaint signal(s) security bugs 2 source links Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
HTTP Security Header praise owner · intel 45.4 · weakness 22.3
praise owner
2 collected complaint signal(s) missing feature support 2 source links Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security headers lockouts, bot/spam defenses, risky access changes, and incident alerts
CSP Friendly Security praise owner · intel 44.7 · weakness 28.1
praise owner
4 collected complaint signal(s) bugs support 2 source links Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security headers lockouts, bot/spam defenses, risky access changes, and incident alerts

Repeated Themes

0 shown

No repeated plugin-level themes have been generated yet.

Collected Signals

19 shown from 19 collected
praise Looks great (5 stars) review · 2021-12-06T15:40:21+00:00 · medium severity · content security policy

Looks great: users praise easy, quality, which suggests what competitors already do well.

Evidence: Looks great …but also simple.
easy quality trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
praise Tagging violations as analyzed, but left on blocked support · 2021-06-06T11:39:01+00:00 · medium severity · content security policy

Tagging violations as analyzed, but left on blocked: users praise value, which suggests what competitors already do well.

Evidence: What we’re thinking about doing is updating the Reported column to display both date and time.
value trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint Php warning in src/controllers/Ajax.php support · 2021-05-30T06:47:53+00:00 · medium severity · content security policy

Php warning in src/controllers/Ajax.php: users show bugs, compatibility pain that may indicate a product gap.

Evidence: Php warning in src/controllers/Ajax.php The following warning has started to appear in the error log: PHP Warning: in_array() expects parameter 2 to be array, null given in /mysite/wp-content/plugins/sea-sp-community-edition/src/controllers/Ajax.php on line 430, referer https://www.mysite.com/some-page/ As it was generated by an unknown visitor to the site,
bugs compatibility trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
mixed Use DB prefix when dropping tables support · 2021-05-16T06:32:08+00:00 · medium severity · content security policy

Use DB prefix when dropping tables: users show bugs, compatibility, performance pain that may indicate a product gap.

Evidence: Use DB prefix when dropping tables Please do not forget to use the local DB prefix in the commands to drop database tables.
bugs compatibility performance setup trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
mixed Redundant directive values redux support · 2021-04-28T15:48:53+00:00 · high severity · content security policy

Redundant directive values redux: users show security, bugs, performance pain that may indicate a product gap.

Evidence: Redundant directive values redux After doing a fresh install of ver.
security bugs performance migration trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint Interpretation of browser error msg when the script is from 3rd party site. support · 2021-03-31T11:52:32+00:00 · high severity · content security policy

Interpretation of browser error msg when the script is from 3rd party site.: users show security, bugs, missing feature pain that may indicate a product gap.

Evidence: Interpretation of browser error msg when the script is from 3rd party site.
security bugs missing feature support trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
praise Redundant directive values support · 2021-03-27T07:47:36+00:00 · low severity · content security policy

Redundant directive values: users praise value, which suggests what competitors already do well.

Evidence: Redundant directive values I note that in the Current Violations tab, when “Include subdomains” is set, the resulting CSP header contains redundant information.
value form trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
question https switch always on support · 2021-03-26T00:02:53+00:00 · medium severity · content security policy

https switch always on: users show bugs, missing feature pain that may indicate a product gap.

Evidence: in frame-ancestors, child-src, connect-src, manifest-src, prefetch-src, script-src-elem, … I’m also missing the possibility to set “upgrade-insecure-requests”, “report-uri” and “object-src” For some header-fields the “https:” switch is always on and cannot be disabled.
bugs missing feature trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
mixed 1.5 Doesnt Desplay Hosted Domain support · 2021-03-25T04:55:48+00:00 · medium severity · content security policy

1.5 Doesnt Desplay Hosted Domain: users show bugs, support pain that may indicate a product gap.

Evidence: 1.5 Doesnt Desplay Hosted Domain Hey Guys, Thanks for fixing the error related to google domains not displaying properly, I still have some completely blank domains showing up and the main domain is just showing up as com now 😐 Thanks for the work on the plugin and I will surely leave a review but once its working effeciently, if you need help testing send m
bugs support value trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint Objects blocked but no clear error message in browser console support · 2021-03-24T14:01:59+00:00 · high severity · content security policy

Objects blocked but no clear error message in browser console: users show security, bugs, compatibility pain that may indicate a product gap.

Evidence: Objects blocked but no clear error message in browser console After updating the plugin to ver 1.5.0 certain elements on a page are being blocked (when the CSP is active), but no error message in displayed in the browser console explaining what directive is concerned.
security bugs compatibility support trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
neutral Database table prefixes support · 2021-03-22T10:57:58+00:00 · medium severity · content security policy

Database table prefixes: users show bugs, performance, support pain that may indicate a product gap.

Evidence: Database table prefixes I note that the tables in the database are named without the prefix defined by the administrator.
bugs performance support trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
mixed Nonce management? support · 2021-03-22T10:55:59+00:00 · medium severity · content security policy

Nonce management?: users show bugs, performance, missing feature pain that may indicate a product gap.

Evidence: I note that the database table ‘seasp_site_settings’ contains a column called ‘nonce_enabled’.
bugs performance missing feature support trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
mixed Doesn’t Display Entire Domain for SOme support · 2021-03-02T05:05:06+00:00 · medium severity · content security policy

Doesn’t Display Entire Domain for SOme: users show bugs, missing feature, support pain that may indicate a product gap.

Evidence: Doesn’t Display Entire Domain for SOme Hey there, thanks for the plugin it really does make life easier, but there are a few issues and features I would request.
bugs missing feature support value trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
mixed WP-Admin access support · 2021-02-08T10:54:52+00:00 · high severity · content security policy

WP-Admin access: users show security, bugs, compatibility pain that may indicate a product gap.

Evidence: WP-Admin access I have SeaSP set in Report Only and Error Correction on.
security bugs compatibility support trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
mixed Current violations gathering support · 2021-02-05T09:39:53+00:00 · high severity · content security policy

Current violations gathering: users show security, bugs, performance pain that may indicate a product gap.

Evidence: I intend to run with Error Collection On for a reasonable time (weeks).
security bugs performance pricing trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
praise Interface makes it easier for beginners (4 stars) review · 2020-10-09T21:07:06+00:00 · high severity · content security policy

Interface makes it easier for beginners: users show security, missing feature, pricing pain that may indicate a product gap.

Evidence: Interface makes it easier for beginners After my initial failed install (see support thread) and subsequent support I came back for a second try with this as an updated version was available.
security missing feature pricing support trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
mixed Great job! support · 2020-10-02T23:01:19+00:00 · high severity · content security policy

Great job!: users show security, missing feature, pricing pain that may indicate a product gap.

Evidence: Great job!
security missing feature pricing support trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
mixed fails to load bootstrap support · 2020-09-27T15:01:07+00:00 · medium severity · content security policy

fails to load bootstrap: users show bugs, compatibility, missing feature pain that may indicate a product gap.

Evidence: fails to load bootstrap Installed twice.
bugs compatibility missing feature pricing trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
praise One of the best security content protector (5 stars) review · 2020-08-20T06:15:52+00:00 · high severity · content security policy

One of the best security content protector: users show security, missing feature, support pain that may indicate a product gap.

Evidence: One of the best security content protector Best plugin when it comes to protecting and managing your content and it also collects the data of you site which violates certain things to help you to find and correct as soon as possible.it also auto mates mail processing making it easier for the user to manage…It also packed up with some ton of awesome feature i
security missing feature support value trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts