Secure your WordPress sites with the Content Security Policy HTTP Header
Content Security Policy HTTP header is a part of the Shield's HTTP Headers module. It helps you to restrict the sources and types of content that may be loaded and processed by visitor browsers.
In essence it allows you to dictate which resources, files, etc. can be loaded/processed by the browser.
How to secure your WordPress sites with CSP header
To secure your site with CSP header in Shield, you'll need to manually add custom CSP rules to your site.
To do this, just enable CSP headers option first and then use 'Manual Rules' option to add your custom rules:
Feel free to provide as many custom Content Security Policy rules as you need to.
Please note that, if you do not provide any CSP rules, CSP headers setting will be turned off - these headers will not be active.
Important: There is no validation that your rules are structured correctly, nor whether they’re appropriate for your particular site and circumstances. Great care should be taken when providing your custom rules and advice should be sought from your web developer on what is most appropriate.
To learn more about HTTP Content Security Policy Headers, read the blog article here.
Note: Apart from the option to manually add custom CSP rules explained above, there were other options in the older plugin releases too. But, due to the complexity of CSP and the superficial nature of our CSP implementation, we've decided to remove those certain CSP options as of the 10.2+ releases. We explore the issue in full detail in our blog post on this topic here.