Plugin Pulse
← Pulse

CSP Friendly Security

by Pascal CESCATO · Security

Also makes 1 other plugin · 6.2K+ installs across the portfolio →

Adds a CSP header compatible with most WP plugins without breaking styles.

⚠ Few reviews
How scoring works →
82 Health · B
Maintenance 100/100
Rating quality 70/100
Support 70/100

82 health vs 64 average across 997 Security plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

89 / 100

Excellent listing optimization

Biggest win: Rating quality

Update recency 100/100
WP compatibility 100/100
Rating quality 54/100
Listing tuning 100/100

To rank higher: Too few reviews to rank on quality — nudge happy users to leave one.

Get the full rank-higher report →

Daily downloads

Since 2022-10-05 · 1,427 days · wp.org + Plugin Pulse archive

+58% vs prior 30d
12Downloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

126

now · peak 181

11830d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

CSP Friendly Securit · #12083 you Content Security Pol · #4842 GD Security Headers · #5874 HTTP Security Header · #5698

Rating trend

Star average over time · dips mark rough releases

3.5Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

590per 1k installs · Aug 26

Release cadence

Occasionally updated
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

1

releases in the last 12 months

3mo ago

latest release · v1.5.2

3

tagged releases on record

Recent releases

1.5.2 · 3mo ago1.5.1 · 1.0y ago1.5.0 · 1.0y ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin · 85% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v1.5 85%
v1.1 15%

Estimated active installs

The public count shows “200+”. Our estimate pins where the real number sits.

tracked estimate
200–300 ≈250

Refined from the date this plugin crossed into its current band.

At the current install trend, crossing 300+ in roughly 200 days.

Install history · since 2022-10-04 · 1,380 observations

200Installs · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A small install base leaves thin data to model from.

Details

Version
1.5.2
Last updated
4d ago
Added
2022-04-21 · 4 yrs old
Requires WP
5.9
Tested up to
7.1
Requires PHP
7.3

Recent reviews

All reviews on wp.org ↗
  1. amanandhishoe
    3.1y ago

    I downloaded this plugin and modified it for my site. I would recommend doing that. The plugin hooks into the ‘template_redirect’ hook. At that point the source for the page has been generated by themes and plugins and is ready to be sent. The plugin looks through the generated source and makes nonces for all inline scripts and styles. It modifies the source so the inline scripts and styles have a nonce=’some-nonce’ statement in them. It creates a Content-Security-Policy which includes those nonces. However, each site has its own CSP needs, and so modifying the plugin to tailor the CSP to your site is not that difficult to do. That is what I have done.

    Read on wp.org ↗
  2. hayobethlehem
    4.0y ago

    doesn’t seem to work properly with w3tc. hope it will get updated at some point.

    Read on wp.org ↗
  3. Anonymous User
    4.0y ago

    The plugin works as advertised however, it does not let you modify the CSP header resulting in a less than ideal CSP header. The header this plugin serves provides no protection against clickjacking and allows all external scripts. This topic was modified 3 years, 10 months ago by anonymized-20439159.

    Read on wp.org ↗
  4. OkorieWare
    4.1y ago

    This is the most ‘straight to the point’ CSP tool that I’ve found. So far, so go.

    Read on wp.org ↗

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 6.8.2

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 1 language, 0 at 90% or more

Dutch (Belgium) 50%

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2026-03-22 100+ → 200+ up after 788 days in tier
  2. 2024-01-24 90+ → 100+ up after 78 days in tier
  3. 2023-11-07 80+ → 90+ up after 2 days in tier
  4. 2023-11-05 90+ → 80+ down after 11 days in tier
  5. 2023-10-25 80+ → 90+ up after 1 days in tier
  6. 2023-10-24 90+ → 80+ down after 1 days in tier
  7. 2023-10-23 80+ → 90+ up after 5 days in tier
  8. 2023-10-18 90+ → 80+ down after 9 days in tier

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for CSP Friendly Security into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/csp-antsst" width="480" height="300" style="border:0" loading="lazy" title="CSP Friendly Security — Plugin Pulse"></iframe>
Preview card ↗

CSP Friendly Security: 200+ active installs, 3.5★ (4 reviews). Plugin Pulse (WP Mayor), as of 2026-08-31. https://plugins.wpmayor.com/plugin/csp-antsst