| 开发者 | scriptsentinel |
|---|---|
| 更新时间 | 2026年9月3日 00:15 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
manage_options administrator may separately activate a complete reviewed candidate. The plugin emits one Content-Security-Policy header only on eligible logged-out public 2xx HTML/XHTML GET and HEAD responses. It excludes private/admin traffic, REST, AJAX, cron, feeds, previews, XML-RPC, CLI, redirects, errors, and non-HTML responses.
Activation checks credential-free public GET and HEAD responses before and after the change. Status distinguishes locally stored state from exact publicly verified delivery. A failed check stays visible and does not silently deactivate or roll back. Administrators can verify again, deactivate, restore one prior state, or use the emergency bypass.
Script Sentinel suppresses its header when PHP/WordPress exposes another enforced CSP. Headers added later by a host, proxy, cache, or CDN are outside PHP's reliable view, so test on staging and inspect the final uncached response.
Premium CSP Autopilot is an optional paid hosted service. Script Sentinel's servers provide recurring verified-site scans, drift comparison, reduced CSP report aggregates, and staged rollout coordination. Payment covers those hosted operations; it does not unlock or extend local CSP controls. Enrollment is explicit. Safe drift can move through report-only observation, simulation, production probation, and exact commit or rollback; trust-expanding or unknown drift waits for approval.
What "up to 10 pages" means
The hosted free WordPress endpoint currently accepts at most one valid scan per canonical site during a rolling 60-minute period. Each scan can visit up to ten eligible public same-origin pages and may reach fewer. This service capacity and abuse-prevention limit applies only to hosted scans; it does not expire or disable local CSP controls.
External service and data use
This plugin uses the Script Sentinel service at https://script-sentinel.com/.
Before an administrator starts a scan or Premium pairing, activation and ordinary administrator-page rendering send nothing to Script Sentinel. After Premium is connected, traffic-driven WP-Cron may start the separately disclosed agent synchronization during any request. When an administrator explicitly clicks Scan, the browser sends to https://script-sentinel.com/api/v1/wordpress/scan:
script-sentinel to /wp-content/plugins/.GET and HEAD verification, test the site, and purge page/CDN caches after changes.No. A complete result remains inactive until an administrator separately chooses Activate latest CSP and confirms the warning. Partial or header-unsafe results cannot be activated.
WordPress accepted the local deployment record. It is not proof that a host, cache, proxy, or CDN delivered it. The plugin reports delivery verified only after cookie-free public GET and HEAD requests reach its eligible response hook and return the exact policy identity.
A cache, server, proxy, CDN, redirect, excluded response, or competing CSP can bypass WordPress output. Purge caches, inspect the final anonymous response, remove competing policies, then verify again. Failure does not automatically remove local state.
Use Deactivate CSP or Restore prior state under Tools. If needed, add define( 'SCRIPT_SENTINEL_DISABLE_CSP', true ); to wp-config.php and purge caches. Deactivating the plugin also stops emission. Remove the bypass only after correcting and testing the policy.
No. Scanning starts from the public canonical URL. WordPress cookies and credentials are not sent. A public crawl cannot prove personalized, ecommerce, membership, consent, geolocation, feature-flag, or time-dependent flows.
No for free manual scans and explicit local CSP deployment. Premium pairing and Autopilot require an eligible verified Script Sentinel account/monitor and explicit administrator enrollment.
The five-minute agent pulls CSP lifecycle commands. Safe candidates are observed in report-only mode, simulated, and tested during bounded enforcement probation before commit. Trust-expanding/unknown candidates wait for exact approval. Missing evidence, violations, conflicts, expiry, downgrade, or disconnect retain or restore the last-known-good local state.