| 开发者 | guidumasperes |
|---|---|
| 更新时间 | 2026年10月4日 00:40 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
csp-report JSON shape.
/wp-json/csp-violation-reporter/v1/report
The plugin does not create or modify Content Security Policy headers. Site owners should configure CSP headers in their web server, hosting dashboard, theme, or security tooling.
Example report endpoint configuration:
Content-Security-Policy: default-src 'self'; report-uri https://example.com/wp-json/csp-violation-reporter/v1/report
For the modern Reporting API, use an HTTPS endpoint:
Reporting-Endpoints: csp-endpoint="https://example.com/wp-json/csp-violation-reporter/v1/report"
Content-Security-Policy: default-src 'self'; report-to csp-endpoint
/wp-content/plugins/.report-to directive.No. This plugin receives and displays CSP violation reports. CSP header generation is intentionally left to your theme, server, security plugin, or hosting environment.
Yes. Browser violation reports are sent without WordPress authentication. Admin views remain protected by the manage_options capability.
No. The document URL is supplied by the sender, so it can be forged. Origin checks reject unrelated sites but are not authentication. Database-backed per-address and site-wide quotas, payload limits and retention reduce abuse. For high-volume attacks, also configure rate limiting at your web server or firewall.
Limits use the connecting address in REMOTE_ADDR. The plugin does not trust client-controlled X-Forwarded-For headers. Configure trusted-proxy address restoration in your web server if a CDN or reverse proxy fronts the site.
Yes. Some browsers report iframe document URLs as about, about:blank, about:srcdoc or blob instead of an HTTP URL. These reports are accepted only with a referrer on this site's origin. Full blob URLs are checked against their embedded HTTP(S) origin. Redacted reports without a local referrer are rejected because their origin cannot be established. Parent referrers also distinguish otherwise identical redacted violations during deduplication.
Cleanup is scheduled hourly with WP-Cron and also runs when reports are accepted or retention settings change. WP-Cron depends on site traffic; on low-traffic sites, configure a server scheduler to trigger WordPress cron. Expired records are removed in batches. The record ceiling is enforced on every accepted request.
Their occurrences are counted, the last-seen time is refreshed, and the latest raw report is retained. The raw JSON is the normalized CSP report body, not the outer Reporting API envelope. Historical 0.1.1 records keep their original data and can be inspected through grouped views.
The endpoint returns HTTP 400 for malformed reports, 403 for foreign document origins, 413 for oversized payloads, and 429 with a Retry-After header for rate limits. Storage failures return HTTP 500 or 503. Accepted requests retain the existing {"stored": N} response format; N counts accepted occurrences, including duplicates.
No. The plugin stores a salted hash of the remote address to help with deduplication and abuse analysis without retaining the raw IP address.
No. Reports are stored in the site's own WordPress database.