{"id":7537,"date":"2026-04-10T02:37:42","date_gmt":"2026-04-10T00:37:42","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=7537"},"modified":"2026-04-10T02:37:43","modified_gmt":"2026-04-10T00:37:43","slug":"asigurati-va-site-ul-cu-pluginul-strict-csp","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/ro\/knowledgebase\/secure-your-site-with-the-strict-csp-plugin\/","title":{"rendered":"Asigura\u021bi-v\u0103 site-ul cu pluginul Strict CSP"},"content":{"rendered":"<div class=\"translation-block translation-block-merged\">\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/secure-your-site-with-the-strict-csp-plugin\/#Secure_Your_Site_with_the_Strict_CSP_Plugin\" >Secure Your Site with the Strict CSP Plugin<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/secure-your-site-with-the-strict-csp-plugin\/#What_is_a_%E2%80%9CStrict%E2%80%9D_CSP\" >What is a &#8220;Strict&#8221; CSP?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/secure-your-site-with-the-strict-csp-plugin\/#How_the_Plugin_Protects_Your_mybox_Site\" >How the Plugin Protects Your mybox Site<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/secure-your-site-with-the-strict-csp-plugin\/#Step-by-Step_Configuration\" >Step-by-Step Configuration<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/secure-your-site-with-the-strict-csp-plugin\/#Problem_Solving_Best_Practices\" >Problem Solving &amp; Best Practices<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/secure-your-site-with-the-strict-csp-plugin\/#Summary\" >Summary<\/a><\/li><\/ul><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Secure_Your_Site_with_the_Strict_CSP_Plugin\"><\/span>Secure Your Site with the Strict CSP Plugin<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"p-rc_41edb21d28659936-79\">Website security goes beyond strong passwords.<sup><\/sup> A critical but often overlooked threat is <strong>Cross-Site Scripting (XSS)<\/strong>, where hackers inject malicious scripts into your site to steal data or redirect users.<sup><\/sup> Implementing a <strong>Content Security Policy (CSP)<\/strong> is one of the most effective defenses against these attacks.<sup><\/sup><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The <strong>Strict CSP<\/strong> plugin for WordPress (v0.3.2 in 2026) is a specialized tool that simplifies the implementation of a &#8220;Strict&#8221; policy, which is significantly more secure than traditional domain allow-lists.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_is_a_%E2%80%9CStrict%E2%80%9D_CSP\"><\/span>What is a &#8220;Strict&#8221; CSP?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<\/div>\n\n<div id=\"mybox-2345026258\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Acces timpuriu<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Mai ave\u021bi nevoie de ajutor?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contacta\u021bi echipa noastr\u0103 de servicii pentru clien\u021bi.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Trimite mesaj<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\" id=\"p-rc_41edb21d28659936-80\">Traditional CSPs work by &#8220;whitelisting&#8221; trusted domains (e.g., <code>google.com<\/code>). However, these are hard to maintain and often easy for hackers to bypass.<sup><\/sup><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"p-rc_41edb21d28659936-81\"><strong>Strict CSP<\/strong> uses a more modern approach called a <strong>nonce<\/strong> (a &#8220;number used once&#8221;).<sup><\/sup><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>For every page load, the plugin generates a random, unique code.<\/li>\n\n\n\n<li>Only scripts that carry this specific code are allowed to run.<\/li>\n\n\n\n<li>Any malicious script injected by a hacker won&#8217;t have the code and will be blocked instantly by the browser.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_the_Plugin_Protects_Your_mybox_Site\"><\/span>How the Plugin Protects Your mybox Site<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"p-rc_41edb21d28659936-84\">The Strict CSP plugin focuses on the frontend and login screens of your WordPress site.<sup><\/sup><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Automated Nonce Injection:<\/strong> It automatically adds the required security tokens to scripts added via standard WordPress functions (like <code>wp_enqueue_script<\/code>).<\/li>\n\n\n\n<li><strong>Embed Protection:<\/strong> It ensures that even scripts from embeds (like YouTube or social media posts) receive the necessary security attributes to function under a strict policy.<\/li>\n\n\n\n<li><strong>XSS Mitigation:<\/strong> By blocking any script that wasn&#8217;t intentionally placed by your theme or plugins, it effectively neutralizes most stored and reflected XSS vulnerabilities.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step-by-Step_Configuration\"><\/span>Step-by-Step Configuration<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Because this plugin enforces a very high level of security, the setup process requires careful verification to ensure your site&#8217;s functionality remains intact.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"p-rc_41edb21d28659936-86\"><strong>1. Installation<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"p-rc_41edb21d28659936-86\">Go to <strong>Plugins &gt; Add New<\/strong>, search for <strong>&#8220;Strict CSP&#8221;<\/strong>, and click <strong>Install<\/strong> and <strong>Activate<\/strong>.<sup><\/sup><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"p-rc_41edb21d28659936-87\"><strong>2. The &#8220;Remember Me&#8221; Requirement<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"p-rc_41edb21d28659936-87\">Once activated, log out of your WordPress dashboard and log back in, ensuring you check the <strong>&#8220;Remember Me&#8221;<\/strong> box.<sup><\/sup> This is a technical requirement for the plugin to maintain your secure session correctly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>3. Monitoring Mode<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The plugin typically starts in a &#8220;Monitoring&#8221; or &#8220;Report-Only&#8221; mode. This allows you to see which scripts would be blocked without actually breaking the site.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Browse your site thoroughly: visit the homepage, contact forms, and galleries.<\/li>\n\n\n\n<li>Check your browser console (F12) for &#8220;CSP Violation&#8221; reports.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>4. Enabling Enforcement<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once you have confirmed that your legitimate theme scripts and plugins are working (because they use standard WordPress enqueueing), you can switch the plugin to active enforcement.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Problem_Solving_Best_Practices\"><\/span>Problem Solving &amp; Best Practices<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Compatibility Check<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Strict CSP plugin works best with modern themes and plugins. If a developer &#8220;hard-coded&#8221; a script tag directly into a template file instead of using <code>wp_enqueue_script<\/code>, that script <strong>will be blocked<\/strong>.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Fix:<\/strong> You may need to manually add a nonce to that specific tag or, better yet, update the theme to follow WordPress coding standards.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Site Editor Consideration<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In 2026, many sites use the <strong>Site Editor (FSE)<\/strong>. The plugin includes a feature to automatically disable itself while you are in the Site Editor to prevent the security policy from interfering with your design tools.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Performance on mybox<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Strict CSP is an extremely lightweight plugin with almost zero impact on server performance. Because the browser does the &#8220;heavy lifting&#8221; of blocking scripts, it is an efficient way to secure your <strong>mybox<\/strong> hosting.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Summary\"><\/span>Summary<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The Strict CSP plugin is a &#8220;set-and-forget&#8221; security upgrade for high-standard WordPress sites. By moving away from easily-bypassed allow-lists to a nonce-based strict policy, you provide your users with one of the strongest possible defenses against modern web threats.<\/p>\n<\/div>","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[58,60],"manual_kb_tag":[419,429,2680,6651,7306,9974,9975,9976,9977,9978],"class_list":["post-7537","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-web-applications-cms","manualknowledgebasecat-wordpress-plugins","manual_kb_tag-wordpress-plugin","manual_kb_tag-wordpress-security","manual_kb_tag-login-security","manual_kb_tag-cross-site-scripting","manual_kb_tag-content-security-policy","manual_kb_tag-strict-content-security-policy","manual_kb_tag-nonce-based-security","manual_kb_tag-nonce-injection","manual_kb_tag-enqueue-scripts","manual_kb_tag-embed-protection"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/7537","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/7537\/revisions"}],"predecessor-version":[{"id":7538,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/7537\/revisions\/7538"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/media?parent=7537"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manualknowledgebasecat?post=7537"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb_tag?post=7537"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}