PluginSift
PluginsThemesCompare
Directory
  • Plugins
  • Themes
  • Compare Plugins
Plugin Comparisons
  • SEO
  • Security
  • Ecommerce
  • Page Builders
  • Caching
  • Backup
  • Forms
  • Analytics
Resources
  • About
  • Contact
  • llms.txt

© 2026 PluginSift. Data sourced from WordPress.org. · [email protected]

  1. Home
  2. Plugins
  3. Security
  4. Strict CSP
Strict CSP icon

Strict CSP

Enforces a Strict Content Security Policy on the frontend and login screen to help mitigate any XSS vulnerabilities.

By Weston Ruter·Security·Free
00
·20 active installs·Updated 4 months ago
DownloadVisit HomepageCompare

As of April 2026, Strict CSP is a WordPress security plugin with 20 active installations and a 0/5 rating0. It has been downloaded 575 times in total. Requires WordPress 6.4+ and PHP 7.2+. Available on WordPress.org since 2025. Top alternative: Wordfence Security – Firewall, Malware….

0/5Rating
20active installs
575total downloads
1 yearsince 2025

Overview

This plugin enforces a Strict Content Security Policy (CSP) on the frontend and login screen. This helps mitigate cross-site scripting (XSS) vulnerabilities. The policy cannot yet be applied to the WP Admin (see #59446).

In #58664, the manual construction of script tags was eliminated from WP_Scripts and inline scripts on frontend/login screen, thanks to the helper functions which had previously been introduced in #39941. This made it possible to apply Strict CSP, as long as themes and plugins are not directly printing <script> tags. Some bundled WordPress core themes still do this incorrectly (which has been reported in Trac as #63806). For example, do not do this:

function my_theme_supports_js() {
    echo '<script>document.body.classList.remove("no-js");<…
Read full description on WordPress.org

Ratings & Reviews

00 reviews
5 ★
0
4 ★
0
3 ★
0
2 ★
0
1 ★
0

Compatibility

WordPress6.4+ requiredTested up to 6.9.4
PHP7.2+ required

Top Alternatives to Strict CSP

Wordfence Security &#8211; Firewall, Malware Scan, and Login Security icon
Wordfence Security – Firewall, Malware…
4.75.0M+ installsUpdated 3 months ago
ViewCompare
Hostinger Tools icon
Hostinger Tools
3.13.0M+ installsUpdated 4 days ago
ViewCompare
Jetpack &#8211; WP Security, Backup, Speed, &amp; Growth icon
Jetpack – WP Security, Backup, Speed, &…
3.83.0M+ installsUpdated 1 month ago
ViewCompare
Really Simple Security &#8211; Simple and Performant Security (formerly Really Simple SSL) icon
Really Simple Security – Simple and…
4.93.0M+ installsUpdated 6 days ago
ViewCompare
Limit Login Attempts Reloaded – Login Security, 2FA, Brute Force Protection &amp; Firewall icon
Limit Login Attempts Reloaded – Login…
4.92.0M+ installsUpdated 1 week ago
ViewCompare
View all security plugins →

Frequently Asked Questions

Changelog

0.3.2

  • Use wp_generate_password() to create CSP nonce instead of using wp_create_nonce(). Props kasparsd. (#13)
View full changelog on WordPress.org

Contributors

Weston RuterWeston Ruter
Plugin Info
Version
0.3.2
Last Updated
Nov 30, 2025
WP Requires
6.4+
Tested Up To
6.9.4
PHP Requires
7.2+
Active Installs
20
Downloads
575
Added
Aug 10, 2025
Business
Community

Tags

security

Developer

W
Weston Ruter
26 plugins0.4M+ total installs
View all plugins →

Quick Compare

Strict CSP vs Wordfence Security – Firewall, Malware…→Strict CSP vs Hostinger Tools→Strict CSP vs Jetpack – WP Security, Backup, Speed, &…→

Plugin data sourced from WordPress.org. Analysis and metrics by PluginSift.