CSP
Content-Security-Policy headers with per-request nonce for Kirby, following Google's strict CSP guidance.
Features
- Opt-in and per-host
- Disabled by default, enable per environment via config.{host}.php
- Report-only rollout
- Test a policy against real traffic before enforcing.
- Per-request nonce
- cspNonce() helper for inline scripts, Vite tags and third-party snippets.
- Panel-safe
- The header is only sent on frontend routes; Panel, API and media are left untouched.
Info
- Topics
Similar plugins
- Locked Pages Password-protect pages easily, Panel blueprint included
-
Kirby S3 Sync Kirby CMS plugin for syncing data to Cloudflare R2 (or any other s3-compatible bucket)
-
Language Access Controls which languages are visible on the frontend and who can edit them in the Panel. Frontend visitors only see the languages you've enaβ¦