CSP Violation Reporter
Collect Content Security Policy violation reports through a WordPress REST endpoint and review them in the admin dashboard.
Use with caution
CSP Violation Reporter works, but test it on a staging site before relying on it in 2026. It runs on 20+ sites, is rated 5/5 and was last updated 4 months ago, and scores 48/100 on our health check.
- Small user base (20+ active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where CSP Violation Reporter stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| content security policy | >100 |
| csp | #3 |
| reporting | >100 |
| reports | >100 |
| security | >100 |
Version adoption
Share of active sites per release.
Rating breakdown
★★★★★★★★★★ 5 from 1 reviews
About CSP Violation Reporter
From the official readme · v0.1.1Description
CSP Violation Reporter adds a public WordPress REST endpoint for browser Content Security Policy violation reports and stores received violations in a local database table.
Reports can be reviewed from Tools > CSP Violations. The plugin supports the modern Reporting API payload format as well as the older csp-report JSON shape.
Endpoint:
/wp-json/csp-violation-reporter/v1/report
The plugin does not create or modify Content Security Policy headers. Site owners should configure CSP headers in their web server, hosting dashboard, theme, or security tooling.
Example report endpoint configuration:
Content-Security-Policy: default-src 'self'; report-uri https://example.com/wp-json/csp-violation-reporter/v1/report
For the modern Reporting API, use an HTTPS endpoint:
Reporting-Endpoints: csp-endpoint="https://example.com/wp-json/csp-violation-reporter/v1/report"
Content-Security-Policy: default-src 'self'; report-to csp-endpoint
Privacy
This plugin stores CSP violation reports submitted by browsers. Stored fields can include the document URL, referrer URL, blocked URI, violated directive, source file, line and column numbers, a user agent string, a salted hash of the remote address, and the raw report payload.
The plugin does not store raw IP addresses and does not transmit report data to external services.
Installation
- Upload the plugin folder to
/wp-content/plugins/. - Activate the plugin through the Plugins screen in WordPress.
- Open Tools > CSP Violations to copy the reporting endpoint.
- Configure your CSP Reporting API group and reference it from your
report-todirective.
Frequently asked questions
Does this plugin set my CSP header?
No. This plugin receives and displays CSP violation reports. CSP header generation is intentionally left to your theme, server, security plugin, or hosting environment.
Is the report endpoint public?
Yes. Browser violation reports are sent without WordPress authentication. Admin views remain protected by the manage_options capability.
Does the plugin store visitor IP addresses?
No. The plugin stores a salted hash of the remote address to help with deduplication and abuse analysis without retaining the raw IP address.
Does the plugin send data to third parties?
No. Reports are stored in the site’s own WordPress database.
Changelog
0.1.1
- Prepared SQL statements that include the plugin’s custom table name.
0.1.0
- Initial development release.
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best CSP Violation Reporter alternatives
All content security policy plugins →FAQ
CSP Violation Reporter: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Sep 29, 2026
Is CSP Violation Reporter free?
Yes. CSP Violation Reporter is free to download and use from the official WordPress.org plugin directory.
Is CSP Violation Reporter safe to use in 2026?
CSP Violation Reporter works, but test it on a staging site before relying on it in 2026. It runs on 20+ sites, is rated 5/5 and was last updated 4 months ago, and scores 48/100 on our health check.
How many websites use CSP Violation Reporter?
CSP Violation Reporter is active on 20+ WordPress websites and has been downloaded 285 times since it launched in May 2026. It was downloaded 89 times in the last 30 days.
Does CSP Violation Reporter work with WordPress 7.1?
CSP Violation Reporter is officially tested up to WordPress 7.0.6, while the latest release is 7.1.2. It may still work, but try it on a staging site first.
What PHP version does CSP Violation Reporter need?
CSP Violation Reporter requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was CSP Violation Reporter last updated?
The latest version, 0.1.1, was released on May 28, 2026 (4 months ago).
Who makes CSP Violation Reporter?
CSP Violation Reporter is developed and maintained by Guilherme Dumas Peres.
What are the best alternatives to CSP Violation Reporter?
The most popular alternatives to CSP Violation Reporter are Cookies and Content Securit… (10K+ installs), Content Security Policy Man… (2K+ installs) and HTTP Security Header (1K+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card