You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在WordPress中配置处于enforcement mode的CSP以有效抵御XSS攻击?

Fixing "No CSP found in enforcement mode" Warning in WordPress (For Non-Developers)

Hey there! I get it—you’re not a full-time developer, just know your way around WordPress and basic HTML/CSS. That CSP warning might sound intimidating, but let’s break this down into simple, actionable steps that don’t require deep coding skills.

First, quick context: Content Security Policy (CSP) is a browser security rule that blocks malicious scripts (like XSS attacks) by limiting where your site can load resources from. The warning means your site isn’t using an enforced CSP right now to protect against those risks.

Option 1: Use a WordPress Plugin (Easiest for Beginners)

This is the simplest route—no code required. Here’s how to do it:

  • Log into your WordPress admin dashboard.
  • Navigate to Plugins > Add New.
  • Search for either WP Content Security Policy or Security Headers (both are built to be beginner-friendly).
  • Install and activate the plugin of your choice.
  • Head to the plugin’s settings page:
    • Look for an option labeled Enforcement Mode (start with "Report-Only" first if you want to test without breaking your site, then switch to "Enforced" once you’re confident).
    • Most plugins come with safe default settings that work for most WordPress sites. If you run into issues (like missing styles or broken scripts), tweak the rules to allow trusted sources (e.g., your site’s domain, Google Fonts, or third-party tools you use like Analytics).

Option 2: Manually Add CSP via Theme Functions (If You Prefer Avoiding Plugins)

If you’d rather not use a plugin, you can add a basic CSP header using your theme’s functions file. Critical note: Use a child theme if possible—this ensures your changes won’t get erased when your main theme updates.

  • Go to Appearance > Theme File Editor in your WordPress admin.
  • On the right sidebar, find and click functions.php (or labeled as Theme Functions).
  • Scroll to the very bottom of the file and paste this code:
function add_basic_csp_header() {
    // Basic CSP tailored for most WordPress sites
    header("Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self';");
}
add_action('send_headers', 'add_basic_csp_header');
  • Click Update File to save your changes.

A Quick Explanation of the Code:

The 'unsafe-inline' and 'unsafe-eval' parts are included because many WordPress themes and plugins rely on inline scripts/styles. Removing them right away might break your site, so we’ll keep them for now. As you get more comfortable, you can refine the rules to be stricter over time.

Testing If It Works

After setting up either option:

  • Open your site in Chrome or Firefox, right-click anywhere on the page, and select Inspect to open DevTools.
  • Switch to the Console tab—you should no longer see that "No CSP found in enforcement mode" warning. If you see new warnings about blocked resources, just adjust your CSP rules to allow those trusted sources.

内容的提问来源于stack exchange,提问作者Waleed

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.29 21:58:15