wobqqq / fortifycsp-plugin
Fortify module for October CMS: sends a Content Security Policy header
Package info
github.com/wobqqq/oc-fortify-csp-plugin
Type:october-plugin
pkg:composer/wobqqq/fortifycsp-plugin
Requires
- php: ^8.2
- composer/installers: ^1.0 || ^2.0
- wobqqq/fortify-plugin: ^1.0.3
Requires (Dev)
- ergebnis/composer-normalize: ^2.48
- friendsofphp/php-cs-fixer: ^3.88
- october/rain: ^4.4
- orchestra/testbench: ^10.6
- pestphp/pest: ^4.1
- phpstan/extension-installer: ^1.4
- phpstan/phpstan: ^2.1
- phpstan/phpstan-deprecation-rules: ^2.0
- phpstan/phpstan-strict-rules: ^2.0
- rector/rector: ^2.2
Suggests
None
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-10-01 20:11:18 UTC
README
CSP adds a Content Security Policy (CSP) header to your site's pages to mitigate XSS and data injection attacks.
This plugin is part of the Fortify ecosystem and extends its security capabilities.
📊 Security Dashboard Widget
Fortify includes a dashboard widget that gives you an overview of your application’s security status.
- Highlights critical vulnerabilities and misconfigurations
- Provides quick access to all security checks and tools
- Helps you identify and fix issues in one place
This widget acts as a central hub, allowing you to monitor and manage your application's security at a glance.
🚀 Features
- Easy CSP configuration
- Mitigates XSS attacks
- Control allowed sources (scripts, styles, images, etc.)
- Improves browser-side security
🔗 Related Plugins
- Fortify – comprehensive security suite
- Admin IP Access – restrict admin panel access by IP
- IP Blocker – manually block specific IP addresses
- Smart IP Blocker – automatic IP blocking based on request rate
- Input Sanitizer – block and sanitize malicious input
📦 Requirements
- PHP 8.2 or higher
- October CMS 3.x or 4.x
- Fortify
📥 Installation
| From | How |
|---|---|
| October CMS Marketplace | octobercms.com/plugin/wobqqq-fortifycsp, or Settings → Updates & Plugins → Install plugins in the backend and search for “Fortify CSP” |
| Artisan | php artisan plugin:install Wobqqq.FortifyCsp |
| Composer | composer require wobqqq/fortifycsp-plugin then php artisan october:migrate |
It needs the Fortify core plugin: Composer installs it with the module; when installing from the marketplace, install Fortify first.
💻 Usage
All configuration and management is handled via the October CMS admin panel.
Admin Panel:
Navigate to Settings -> Fortify and enable CSP. Configure allowed sources as needed.
Console Commands:
- Disable CSP module:
php artisan wobqqq.fortify:csp:disable
⬆️ Upgrading
- 1.0.4 — installing the module with Composer installs the Fortify core with it. Nothing changes on an existing site.
- 1.0.3 — a directive value must be a single source expression (such as
'self',https://cdn.example.comordata:); a stored value containing;,,, spaces or control characters is no longer sent, since it could add directives or break the header. The directives are separated by;. Saved settings take effect at once.
⚠️ Good to know
- The header is sent with the site's front-end pages only; the backend keeps October's own headers.
- The default policy allows
'unsafe-inline'and anyhttps:source so that an existing site keeps working. Tighten it (nonces or hashes instead of'unsafe-inline', the hosts you use instead ofhttps:) and check the browser console for blocked resources before relying on it. - Another middleware, the web server or a CDN may set or override
Content-Security-Policy; keep one place in charge of the header.
🔒 Security
Please report a vulnerability privately, as described in SECURITY.md.
🛠️ Development
The toolchain runs in Docker, the host needs nothing but docker and make. The module is tested together with the Fortify core, which Composer installs from Packagist.
make install # composer install make code.fix # composer normalize, Rector, PHP CS Fixer make code.check # composer validate/audit, php -l, YAML lint, PHP CS Fixer, Rector, PHPStan (level max) make test.coverage # Pest with coverage (90 % minimum) make ready # everything above
Every pull request runs the same checks on GitHub Actions, plus a syntax check on PHP 8.2 and a run against the latest core. Pushing a tag that matches the last version in updates/version.yaml publishes it as a GitHub release and to the October CMS marketplace once CI has passed.