Wannes Debusschere Wannes Debusschere

CSP

Content-Security-Policy headers with per-request nonce for Kirby, following Google's strict CSP guidance.

Manual

Download

… and extract the folder to site/plugins/csp

Composer

Git Submodule

Features

🎚 Opt-in and per-host
Disabled by default, enable per environment via config.{host}.php
πŸ§ͺ Report-only rollout
Test a policy against real traffic before enforcing.
πŸ”‘ Per-request nonce
cspNonce() helper for inline scripts, Vite tags and third-party snippets.
πŸ›‘ Panel-safe
The header is only sent on frontend routes; Panel, API and media are left untouched.
Version
1.0.2
License
MIT
Stars
1
Supports
K5 K4
Latest releases