BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
CSP Violation Reporter icon
Maintained Tested up to 7.0.6 #8 in content security policy

CSP Violation Reporter

Collect Content Security Policy violation reports through a WordPress REST endpoint and review them in the admin dashboard.

Active installs20+10+ tier
Downloads · 30d89▲ +56.1% vs prev. 30d
Rating5/51 reviews
Health score48/100Fair
All-time downloads285Since May 2026
Support resolved0 / 10% in last 2 months
RequiresWP 6.5PHP 7.4+
Downloads · 7d15▼ -21.1% week over week
Our verdict

Use with caution

CSP Violation Reporter works, but test it on a staging site before relying on it in 2026. It runs on 20+ sites, is rated 5/5 and was last updated 4 months ago, and scores 48/100 on our health check.

  • Small user base (20+ active installs)
  • Very few reviews so far

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

257Jul 1Aug 14Sep 28
Yesterday0
Daily average (1y)2
Peak day35May 28, 2026
Last 12 months287

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where CSP Violation Reporter stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
content security policy >100 4,841 Best content security policy plugins →
csp #3 226 Best csp plugins →
reporting >100 3,926 Best reporting plugins →
reports >100 10,000 Best reports plugins →
security >100 10,000 Best security plugins →

Version adoption

Share of active sites per release.

  • 0.1100.0%

Rating breakdown

★★★★★★★★★★ 5 from 1 reviews

  • 5★100.0%
  • 4★0.00%
  • 3★0.00%
  • 2★0.00%
  • 1★0.00%

About CSP Violation Reporter

From the official readme · v0.1.1

Description

CSP Violation Reporter adds a public WordPress REST endpoint for browser Content Security Policy violation reports and stores received violations in a local database table.

Reports can be reviewed from Tools > CSP Violations. The plugin supports the modern Reporting API payload format as well as the older csp-report JSON shape.

Endpoint:

/wp-json/csp-violation-reporter/v1/report

The plugin does not create or modify Content Security Policy headers. Site owners should configure CSP headers in their web server, hosting dashboard, theme, or security tooling.

Example report endpoint configuration:

Content-Security-Policy: default-src 'self'; report-uri https://example.com/wp-json/csp-violation-reporter/v1/report

For the modern Reporting API, use an HTTPS endpoint:

Reporting-Endpoints: csp-endpoint="https://example.com/wp-json/csp-violation-reporter/v1/report"

Content-Security-Policy: default-src 'self'; report-to csp-endpoint

Privacy

This plugin stores CSP violation reports submitted by browsers. Stored fields can include the document URL, referrer URL, blocked URI, violated directive, source file, line and column numbers, a user agent string, a salted hash of the remote address, and the raw report payload.

The plugin does not store raw IP addresses and does not transmit report data to external services.

Installation

  1. Upload the plugin folder to /wp-content/plugins/.
  2. Activate the plugin through the Plugins screen in WordPress.
  3. Open Tools > CSP Violations to copy the reporting endpoint.
  4. Configure your CSP Reporting API group and reference it from your report-to directive.

Frequently asked questions

Does this plugin set my CSP header?

No. This plugin receives and displays CSP violation reports. CSP header generation is intentionally left to your theme, server, security plugin, or hosting environment.

Is the report endpoint public?

Yes. Browser violation reports are sent without WordPress authentication. Admin views remain protected by the manage_options capability.

Does the plugin store visitor IP addresses?

No. The plugin stores a salted hash of the remote address to help with deduplication and abuse analysis without retaining the raw IP address.

Does the plugin send data to third parties?

No. Reports are stored in the site’s own WordPress database.

Changelog

0.1.1

  • Prepared SQL statements that include the plugin’s custom table name.

0.1.0

  • Initial development release.

Full changelog on WordPress.org →

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best CSP Violation Reporter alternatives

All content security policy plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Cookies and Content Security Policy Cookies and Content Security Policy Be fully GDPR and CCPA compliant through Content Security Policy. Blocks cookies and… by Johan Jonk Stenström 10K+ ★★★★★★★★★★ 4.9 (67) 1 month ago 75
2 Content Security Policy Manager Content Security Policy Manager Plugin for configuring Content Security Policy headers for your site. Allows different CSP… by Patrick Sletvold 2K+ ★★★★★★★★★★ 4.3 (6) 4 years ago 37
3 HTTP Security Header HTTP Security Header Add and manage essential HTTP security headers with ease. Protect your WordPress site from… by MOHIT GOYAL 1K+ ★★★★★★★★★★ 5 (3) 9 months ago 49
4 GD Security Headers GD Security Headers Configure various security-related HTTP headers, including CSP, XSS, Referrer Policy and… by Milan Petrovic 1K+ ★★★★★★★★★★ 4 (8) 5 months ago 63
5 Security Header Generator Security Header Generator This plugin generates the proper security HTTP response headers to keep your site secured. by Kevin Pirnie 500+ ★★★★★★★★★★ 4.8 (6) 4 days ago 85
6 CSP Friendly Security CSP Friendly Security Adds a CSP header compatible with most WP plugins without breaking styles. by Pascal CESCATO 200+ ★★★★★★★★★★ 3.5 (4) 1 month ago 68
7 No unsafe-inline No unsafe-inline No unsafe-inline helps you to build a Content Security Policy avoiding to use… by Giuseppe 200+ ★★★★★★★★★★ 5 (5) 10 months ago 42
9 GDPR Helper using CSP GDPR Helper using CSP This plugin allows easy addition of Content Security Policy by bpassini 20+ ★★★★★★★★★★ No reviews 4 years ago 24
10 SeaSP Community Edition SeaSP Community Edition SeaSP Community Edition is an automated Content Security Policy Manager. SeaSP allows you… by bluetriangle 20+ ★★★★★★★★★★ 4.7 (3) 5 years ago 30
11 Abdal Security Headers Abdal Security Headers Enhance WordPress security with HTTP security headers and a Smart CSP Assistant that… by Ebrahim Shafiei (EbraSha) 10+ ★★★★★★★★★★ 5 (2) 4 weeks ago 73

FAQ

CSP Violation Reporter: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Sep 29, 2026

Is CSP Violation Reporter free?

Yes. CSP Violation Reporter is free to download and use from the official WordPress.org plugin directory.

Is CSP Violation Reporter safe to use in 2026?

CSP Violation Reporter works, but test it on a staging site before relying on it in 2026. It runs on 20+ sites, is rated 5/5 and was last updated 4 months ago, and scores 48/100 on our health check.

How many websites use CSP Violation Reporter?

CSP Violation Reporter is active on 20+ WordPress websites and has been downloaded 285 times since it launched in May 2026. It was downloaded 89 times in the last 30 days.

Does CSP Violation Reporter work with WordPress 7.1?

CSP Violation Reporter is officially tested up to WordPress 7.0.6, while the latest release is 7.1.2. It may still work, but try it on a staging site first.

What PHP version does CSP Violation Reporter need?

CSP Violation Reporter requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was CSP Violation Reporter last updated?

The latest version, 0.1.1, was released on May 28, 2026 (4 months ago).

Who makes CSP Violation Reporter?

CSP Violation Reporter is developed and maintained by Guilherme Dumas Peres.

What are the best alternatives to CSP Violation Reporter?

The most popular alternatives to CSP Violation Reporter are Cookies and Content Securit… (10K+ installs), Content Security Policy Man… (2K+ installs) and HTTP Security Header (1K+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.