{"id":7560,"date":"2026-04-10T03:10:47","date_gmt":"2026-04-10T01:10:47","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=7560"},"modified":"2026-04-10T03:10:48","modified_gmt":"2026-04-10T01:10:48","slug":"csp-strict-activarea-in-siguranta-a-politicii-de-securitate-a-continutului-in-wordpress","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/ro\/knowledgebase\/strict-csp-safely-enabling-content-security-policy-in-wordpress\/","title":{"rendered":"Strict CSP: Activarea \u00een siguran\u021b\u0103 a politicii de securitate a con\u021binutului \u00een WordPress"},"content":{"rendered":"<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\" id=\"p-rc_5481dc7efad66658-308\">Implementing a Content Security Policy (CSP) is one of the most effective ways to protect your <strong>mybox<\/strong> website from Cross-Site Scripting (XSS) and data injection attacks.<sup><\/sup> However, a manual CSP can easily &#8220;break&#8221; a site by blocking legitimate scripts.<sup><\/sup><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"p-rc_5481dc7efad66658-309\">The <strong>Strict CSP<\/strong> plugin (v0.3.x) is a specialized security tool that automates the deployment of a &#8220;Strict&#8221; policy using <strong>nonces<\/strong> (random, one-time-use numbers).<sup><\/sup> This ensures that only scripts explicitly authorized by WordPress can execute, while blocking unauthorized or malicious code.<\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1' ><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/strict-csp-safely-enabling-content-security-policy-in-wordpress\/#What_is_Strict_CSP\" >What is Strict CSP?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/strict-csp-safely-enabling-content-security-policy-in-wordpress\/#How_It_Works_The_Nonce_Mechanism\" >How It Works: The Nonce Mechanism<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/strict-csp-safely-enabling-content-security-policy-in-wordpress\/#Installation_and_First_Steps\" >Installation and First Steps<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/strict-csp-safely-enabling-content-security-policy-in-wordpress\/#Impact_on_Themes_and_Plugins_Refactoring_Code\" >Impact on Themes and Plugins (Refactoring Code)<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/strict-csp-safely-enabling-content-security-policy-in-wordpress\/#Best_Practices_for_2026\" >Best Practices for 2026<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/strict-csp-safely-enabling-content-security-policy-in-wordpress\/#Common_Problems_and_Diagnosis\" >Common Problems and Diagnosis<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/strict-csp-safely-enabling-content-security-policy-in-wordpress\/#Summary\" >Summary<\/a><\/li><\/ul><\/nav><\/div>\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_is_Strict_CSP\"><\/span>What is Strict CSP?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<\/div>\n\n<div id=\"mybox-1477721478\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Acces timpuriu<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Mai ave\u021bi nevoie de ajutor?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contacta\u021bi echipa noastr\u0103 de servicii pentru clien\u021bi.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Trimite mesaj<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\" id=\"p-rc_5481dc7efad66658-310\">Strict CSP is a lightweight plugin designed to harden the <strong>frontend<\/strong> and the <strong>login screen<\/strong> of your WordPress site.<sup><\/sup><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>XSS Mitigation:<\/strong> It adds a unique <code>nonce<\/code> to every legitimate script tag. The browser will only execute scripts that carry this specific code.<\/li>\n\n\n\n<li><strong>Modern Standards:<\/strong> In 2026, it is optimized for <strong>WordPress 7.0<\/strong>, supporting the new <strong>Abilities API<\/strong> and script modules to ensure security doesn&#8217;t interfere with modern site functionality.<\/li>\n\n\n\n<li><strong>Targeted Protection:<\/strong> It intentionally leaves the <strong>Admin Panel<\/strong> and <strong>Site Editor<\/strong> unaffected to prevent conflicts with complex backend editing tools, focusing its protection where users are most vulnerable.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_It_Works_The_Nonce_Mechanism\"><\/span>How It Works: The Nonce Mechanism<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Traditional CSPs rely on &#8220;allow-listing&#8221; domains (e.g., <code>google.com<\/code>), which are difficult to maintain. Strict CSP uses a &#8220;Nonce + Strict-Dynamic&#8221; approach:<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>Generate:<\/strong> Every time a page loads, the plugin generates a random string (the nonce).<\/li>\n\n\n\n<li><strong>Attach:<\/strong> It attaches this nonce to scripts added via standard WordPress functions (like <code>wp_enqueue_script<\/code>).<\/li>\n\n\n\n<li><strong>Validate:<\/strong> The browser checks every script. If a script has the correct nonce, it runs. If a hacker tries to inject a script, it won&#8217;t have the nonce and will be <strong>blocked instantly<\/strong>.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Installation_and_First_Steps\"><\/span>Installation and First Steps<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">On your <strong>mybox<\/strong> server, the implementation follows a specific safety sequence:<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>Installation:<\/strong> Go to <strong>Plugins > Add New<\/strong>, search for <strong>&#8220;Strict CSP&#8221;<\/strong>, and click <strong>Activate<\/strong>.<\/li>\n\n\n\n<li><strong>Initialization:<\/strong> Log out of your dashboard and log back in, checking the <strong>&#8220;Remember Me&#8221;<\/strong> box. This allows the plugin to properly set its security context for your session.<\/li>\n\n\n\n<li><strong>Monitoring Mode:<\/strong> Initially, the plugin acts in &#8220;Report-Only&#8221; mode. Browse your site\u2014visit the homepage, galleries, and contact forms.<\/li>\n\n\n\n<li><strong>Console Check:<\/strong> Open your browser console (F12). If you see &#8220;CSP Violation&#8221; errors for scripts you <em>know<\/em> are legitimate, it means they aren&#8217;t being enqueued properly (see the &#8220;Customizing Code&#8221; section below).<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Impact_on_Themes_and_Plugins_Refactoring_Code\"><\/span>Impact on Themes and Plugins (Refactoring Code)<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">For Strict CSP to work, your site must follow modern WordPress coding standards. <strong>Manual <code>&lt;script&gt;<\/code> tags<\/strong> or <strong>inline event handlers<\/strong> (like <code>onclick<\/code>) will be blocked.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><td><strong>Blocked Pattern (Unsafe)<\/strong><\/td><td><strong>Recommended Fix (Strict-Ready)<\/strong><\/td><\/tr><\/thead><tbody><tr><td><code>echo '&lt;script&gt;alert(\"Hi\");&lt;\/script&gt;';<\/code><\/td><td>Use <code>wp_add_inline_script()<\/code> or <code>wp_print_inline_script_tag()<\/code>.<\/td><\/tr><tr><td><code>&lt;button onclick=\"doSomething()\"&gt;<\/code><\/td><td>Use <code>addEventListener<\/code> in an external JS file.<\/td><\/tr><tr><td>Hard-coded external scripts in <code>header.php<\/code>.<\/td><td>Use <code>wp_enqueue_script()<\/code> in your <code>functions.php<\/code>.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Best_Practices_for_2026\"><\/span>Best Practices for 2026<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Avoid <code>unsafe-inline<\/code>:<\/strong> While it&#8217;s tempting to use <code>unsafe-inline<\/code> to fix errors, it significantly weakens your security. It is better to refactor the offending code.<\/li>\n\n\n\n<li><strong>Abilities API Integration:<\/strong> If you are using WordPress 7.0&#8217;s new <strong>Abilities API<\/strong>, ensure your script modules are enqueued using the standard API to automatically receive the security nonce.<\/li>\n\n\n\n<li><strong>Test External Embeds:<\/strong> Features like YouTube embeds or X (Twitter) feeds often load their own scripts. Strict CSP includes built-in logic to handle these, but always verify them in the console after activation.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Common_Problems_and_Diagnosis\"><\/span>Common Problems and Diagnosis<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>&#8220;My image slider stopped working!&#8221;<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The slider likely uses an inline script or a hard-coded tag. Check the browser console. You will see a message like: <em>\u201cRefused to execute script because it violates the following Content Security Policy&#8230;\u201d<\/em> * <strong>The Fix:<\/strong> Move that script&#8217;s logic into a separate <code>.js<\/code> file and enqueue it properly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>&#8220;Does this work with my caching plugin?&#8221;<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On <strong>mybox<\/strong>, the plugin is compatible with most caching tools (like LiteSpeed or WP Rocket). However, because nonces must be unique for every request, you may need to ensure your cache is configured to handle &#8220;nonce-aware&#8221; pages or disable the plugin&#8217;s nonce feature on heavily cached static pages.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Summary\"><\/span>Summary<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Strict CSP is not a &#8220;magic firewall&#8221;\u2014it is a policy that enforces professional coding standards. By migrating to a nonce-based security model on your <strong>mybox<\/strong> site, you create a robust defense that protects your visitors from modern XSS threats while ensuring your site remains fast and compliant with 2026 web standards.<\/p>\n<\/div>","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[58,60],"manual_kb_tag":[429,6651,7306,9912,9913,9914,9915,9916,9917,9918],"class_list":["post-7560","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-web-applications-cms","manualknowledgebasecat-wordpress-plugins","manual_kb_tag-wordpress-security","manual_kb_tag-cross-site-scripting","manual_kb_tag-content-security-policy","manual_kb_tag-nonce-mechanism","manual_kb_tag-script-nonce","manual_kb_tag-strict-dynamic","manual_kb_tag-strict-plugin","manual_kb_tag-frontend-security","manual_kb_tag-login-screen-security","manual_kb_tag-report-only-mode"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/7560","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/7560\/revisions"}],"predecessor-version":[{"id":7561,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/7560\/revisions\/7561"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/media?parent=7560"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manualknowledgebasecat?post=7560"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb_tag?post=7560"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}