Plugin Pulse
← Pulse
C

Content Security Policy Manager

by Patrick Sletvold · Security

Also makes 1 other plugin · 2.6K+ installs across the portfolio →

Plugin for configuring Content Security Policy headers for your site. Allows different CSP headers for admin, logged inn frontend and regular visitors

⚠ Stale⚠ Likely abandoned⚠ Few reviews
How scoring works →
45 Health · D
Maintenance 3/100
Rating quality 76/100
Support 70/100

45 health vs 64 average across 997 Security plugins

Removal-risk signals

53/100

Maintenance and integrity signals that tend to precede a WordPress.org removal. Not an official status, a heads-up to act.

  • Long abandoned. No update in 4+ years — the top precursor to removal once a vulnerability is found.
  • Falling behind WordPress. Tested up to WordPress 6.1.12.

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

50 / 100

Room to improve

Biggest win: Update recency

Update recency 8/100
WP compatibility 46/100
Rating quality 57/100
Listing tuning 100/100

To rank higher: Last updated 1481 days ago — ship an update; wp.org decays a listing's search weight after ~180 days.

Get the full rank-higher report →

Daily downloads

Since 2022-10-05 · 1,425 days · wp.org + Plugin Pulse archive

+33% vs prior 30d
0Downloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

370

now · peak 1.1K

37230d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

Content Security Pol · #4830 you GD Security Headers · #5871 Security Header Gene · #9033 Prevent XSS Vulnerab · #2803

Rating trend

Star average over time · dips mark rough releases

4.3Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

186per 1k installs · Aug 26

Release cadence

No release in a year
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

0

releases in the last 12 months

4.1y ago

latest release · v1.2.1

4

tagged releases on record

Recent releases

1.2.1 · 4.1y ago1.2.0 · 4.7y ago1.1.0 · 5.4y ago1.0.0 · 5.4y ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin · 99% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v1.2 99%
v1.1 1.2%

Estimated active installs

The public count shows “2K+”. Our estimate pins where the real number sits.

tracked estimate
2K–3K ≈2.9K

Refined from the date this plugin crossed into its current band.

Install history · since 2021-06-13 · 1,429 observations

2KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A small install base leaves thin data to model from.

Details

Version
1.2.1
Last updated
4.1y ago
Added
2020-07-21 · 6 yrs old
Requires WP
4.6
Tested up to
6.1.12
Requires PHP
7.2

Recent reviews

All reviews on wp.org ↗
  1. ningmorris
    3.1y ago

    Hello, Since report-uri is no longer recommended anymore, I need to use report-to to send CSP reports. But for reason, it doesn’t send reports with report-to. My CSP settings are as follows: In Policy: report-to filed, I filled in csp-endpoint , in Frontend Policy Report-To Header field, I filled in the following JSON data { "group": "csp-endpoint", "max_age": 10886400, "endpoints": [ { "url": "{CSP REPORT ENDPOINT}" } ] } After saving changes in the CMS, all the commas disappeared in Frontend Policy Report-To Header field. { "group": "csp-endpoint" "max_age": 10886400 "endpoints": [ { "url": "{CSP REPORT ENDPOINT}" } ] } I am wondering if you can help to take a look at it, thanks! Note: I have no problem with report-uri. This topic was modified 3 years ago by ningmorris.

    Read on wp.org ↗
  2. rintelengrafik
    3.5y ago

    As soon as I leave the backend the view of my side is without any CSS. Only the plain HTML.

    Read on wp.org ↗
  3. buzibuzi
    3.6y ago

    We are really happy with this plugin.im wondering if you provide a filter so i can merge some dynamic ‘nonce-xx’ to the policy header. this could be very very useful.

    Read on wp.org ↗
  4. Jason Robinson
    4.4y ago

    This plugin is well thought out and does what I need it to. It has also helped me troubleshoot other website’s CSP that wasn’t working correctly, and the documentation is solid if brief.

    Read on wp.org ↗
  5. jeebeezebee
    4.8y ago

    Ce plugin m;a fait gagner des heures de travail.

    Read on wp.org ↗
  6. c3idesign
    5.3y ago

    Great plugin, thank you.

    Read on wp.org ↗

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. Version 1.2.1 Fix error caused by improperly checking the chosen CSP mode when outputting headers (thanks @reatlat). 1.2.1
  2. Version 1.2.0 Improved UI, with CSP directives divided into collapsible categories. Add all remaining non-deprecated CSP directives. Warn if enabling upgrade-insecure-requests on a site that does not support HTTPS. Sanitize directives 1.2.0
  3. Version 1.1.0 This is a relatively small update, that only contains a few more CSP directives. The next update will contain even more, along with an updated user interface. Add some commonly used CSP headers that were missing (thanks 1.1.0
  4. Version 1.0.0 First version. Support for different policies for admin, logged-in frontend and regular visitors. Different policies can have different reporting/enforcing mode. Directives can be configured separately, to easier see wha 1.0.0

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 7.4.8 · WP 6.0.1

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 1 language, 0 at 90% or more

Norwegian (Bokmål) 86%

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2024-12-28 3K+ → 2K+ down after 1 days in tier
  2. 2024-12-27 2K+ → 3K+ up after 4 days in tier
  3. 2024-12-23 3K+ → 2K+ down after 552 days in tier
  4. 2023-06-20 2K+ → 3K+ up after 5 days in tier
  5. 2023-06-15 3K+ → 2K+ down after 2 days in tier
  6. 2023-06-13 2K+ → 3K+ up after 214 days in tier
  7. 2022-11-11 1K+ → 2K+ up

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for Content Security Policy Manager into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/csp-manager" width="480" height="300" style="border:0" loading="lazy" title="Content Security Policy Manager — Plugin Pulse"></iframe>
Preview card ↗

Content Security Policy Manager: 2K+ active installs, 4.3★ (6 reviews). Plugin Pulse (WP Mayor), as of 2026-08-29. https://plugins.wpmayor.com/plugin/csp-manager