Linux 软件免费装

CSP Violation Reporter

开发者 guidumasperes
更新时间 2026年10月4日 00:40
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

security reporting reports csp content-security-policy

下载

0.1.1 0.2.0

详情介绍:

CSP Violation Reporter helps site administrators investigate Content Security Policy violations. It receives browser reports through a public WordPress REST endpoint, stores them in the site's own database, and provides a searchable administrative dashboard. Reports can be reviewed from Tools > CSP Violations. The plugin supports the modern Reporting API payload format as well as the older csp-report JSON shape. Filter by directive, disposition, URL and date range, or group violations by resource. Repeated violations with the same document, blocked resource, directive, policy and source location share one record with an occurrence count. Each record includes first/last-seen timestamps and the latest raw JSON report. Protection is enabled by default: Retention and quotas can be adjusted in Tools > CSP Violations > Settings. Existing reports are preserved during schema upgrades; retention rules also apply to pre-upgrade reports. Endpoint: /wp-json/csp-violation-reporter/v1/report The plugin does not create or modify Content Security Policy headers. Site owners should configure CSP headers in their web server, hosting dashboard, theme, or security tooling. Example report endpoint configuration: Content-Security-Policy: default-src 'self'; report-uri https://example.com/wp-json/csp-violation-reporter/v1/report For the modern Reporting API, use an HTTPS endpoint: Reporting-Endpoints: csp-endpoint="https://example.com/wp-json/csp-violation-reporter/v1/report" Content-Security-Policy: default-src 'self'; report-to csp-endpoint

安装:

  1. Upload the plugin folder to /wp-content/plugins/.
  2. Activate the plugin through the Plugins screen in WordPress.
  3. Open Tools > CSP Violations to copy the reporting endpoint.
  4. Configure your CSP Reporting API group and reference it from your report-to directive.

升级注意事项:

0.2.0 Back up your database. Enables origin checks, rate limits, 30-day retention and a 10,000-record cap by default, including old reports. Review Tools > CSP Violations > Settings. Endpoint URL unchanged.

常见问题:

Does this plugin set my CSP header?

No. This plugin receives and displays CSP violation reports. CSP header generation is intentionally left to your theme, server, security plugin, or hosting environment.

Is the report endpoint public?

Yes. Browser violation reports are sent without WordPress authentication. Admin views remain protected by the manage_options capability.

Does origin validation authenticate the sender?

No. The document URL is supplied by the sender, so it can be forged. Origin checks reject unrelated sites but are not authentication. Database-backed per-address and site-wide quotas, payload limits and retention reduce abuse. For high-volume attacks, also configure rate limiting at your web server or firewall.

How are proxies and CDNs handled?

Limits use the connecting address in REMOTE_ADDR. The plugin does not trust client-controlled X-Forwarded-For headers. Configure trusted-proxy address restoration in your web server if a CDN or reverse proxy fronts the site.

Are iframe violations supported?

Yes. Some browsers report iframe document URLs as about, about:blank, about:srcdoc or blob instead of an HTTP URL. These reports are accepted only with a referrer on this site's origin. Full blob URLs are checked against their embedded HTTP(S) origin. Redacted reports without a local referrer are rejected because their origin cannot be established. Parent referrers also distinguish otherwise identical redacted violations during deduplication.

When does automatic cleanup run?

Cleanup is scheduled hourly with WP-Cron and also runs when reports are accepted or retention settings change. WP-Cron depends on site traffic; on low-traffic sites, configure a server scheduler to trigger WordPress cron. Expired records are removed in batches. The record ceiling is enforced on every accepted request.

Are repeated reports discarded?

Their occurrences are counted, the last-seen time is refreshed, and the latest raw report is retained. The raw JSON is the normalized CSP report body, not the outer Reporting API envelope. Historical 0.1.1 records keep their original data and can be inspected through grouped views.

What happens when the endpoint rejects a report?

The endpoint returns HTTP 400 for malformed reports, 403 for foreign document origins, 413 for oversized payloads, and 429 with a Retry-After header for rate limits. Storage failures return HTTP 500 or 503. Accepted requests retain the existing {"stored": N} response format; N counts accepted occurrences, including duplicates.

Does the plugin store visitor IP addresses?

No. The plugin stores a salted hash of the remote address to help with deduplication and abuse analysis without retaining the raw IP address.

Does the plugin send data to third parties?

No. Reports are stored in the site's own WordPress database.

更新日志:

0.2.0 0.1.1 0.1.0