CSP Friendly Security
by Pascal CESCATO · Security
Also makes 1 other plugin · 6.2K+ installs across the portfolio →
Adds a CSP header compatible with most WP plugins without breaking styles.
82 health vs 64 average across 997 Security plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Biggest win: Rating quality
To rank higher: Too few reviews to rank on quality — nudge happy users to leave one.
Get the full rank-higher report →Daily downloads
Since 2022-10-05 · 1,427 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
126
now · peak 181
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Occasionally updatedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
1
releases in the last 12 months
3mo ago
latest release · v1.5.2
3
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 85% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “200+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
At the current install trend, crossing 300+ in roughly 200 days.
Install history · since 2022-10-04 · 1,380 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A small install base leaves thin data to model from.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ amanandhishoe3.1y ago
I downloaded this plugin and modified it for my site. I would recommend doing that. The plugin hooks into the ‘template_redirect’ hook. At that point the source for the page has been generated by themes and plugins and is ready to be sent. The plugin looks through the generated source and makes nonces for all inline scripts and styles. It modifies the source so the inline scripts and styles have a nonce=’some-nonce’ statement in them. It creates a Content-Security-Policy which includes those nonces. However, each site has its own CSP needs, and so modifying the plugin to tailor the CSP to your site is not that difficult to do. That is what I have done.
Read on wp.org ↗ - ★★★★★ hayobethlehem4.0y ago
doesn’t seem to work properly with w3tc. hope it will get updated at some point.
Read on wp.org ↗ - ★★★★★ Anonymous User4.0y ago
The plugin works as advertised however, it does not let you modify the CSP header resulting in a less than ideal CSP header. The header this plugin serves provides no protection against clickjacking and allows all external scripts. This topic was modified 3 years, 10 months ago by anonymized-20439159.
Read on wp.org ↗ - ★★★★★ OkorieWare4.1y ago
This is the most ‘straight to the point’ CSP tool that I’ve found. So far, so go.
Read on wp.org ↗
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 6.8.2
Languages
via translate.wordpress.orgTranslated into 1 language, 0 at 90% or more
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2026-03-22 100+ → 200+ up after 788 days in tier
- 2024-01-24 90+ → 100+ up after 78 days in tier
- 2023-11-07 80+ → 90+ up after 2 days in tier
- 2023-11-05 90+ → 80+ down after 11 days in tier
- 2023-10-25 80+ → 90+ up after 1 days in tier
- 2023-10-24 90+ → 80+ down after 1 days in tier
- 2023-10-23 80+ → 90+ up after 5 days in tier
- 2023-10-18 90+ → 80+ down after 9 days in tier
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
- C Content Security Policy Manager 2K+ installs · 4.0★ · 3 shared tags D
-
GD Security Headers 1K+ installs · 3.9★ · 2 shared tags B
-
HTTP Security Header 1K+ installs · 4.1★ · 2 shared tags B -
Security Header Generator 500+ installs · 4.2★ · 2 shared tags A -
No unsafe-inline 200+ installs · 4.2★ · 2 shared tags B - G GDPR Helper using CSP 10+ installs · 3.6★ · 2 shared tags D
Embed this report card
Drop a live Pulse card for CSP Friendly Security into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/csp-antsst" width="480" height="300" style="border:0" loading="lazy" title="CSP Friendly Security — Plugin Pulse"></iframe> CSP Friendly Security: 200+ active installs, 3.5★ (4 reviews). Plugin Pulse (WP Mayor), as of 2026-08-31. https://plugins.wpmayor.com/plugin/csp-antsst