WordPress plugin profile

Script Sentinel

Scan up to 10 public pages, review a generated CSP, deploy it locally, and optionally automate safe CSP drift handling.

Version0.1.0
Active installsNew
Rating0.0 / 5
Tested toWP 7.1

About this plugin

Script Sentinel gives administrators a free, manual scan of the canonical public home page and up to nine additional same-origin pages. It displays a generated Content Security Policy (CSP), score, page count, and warnings. WordPress scans take no screenshots. A scan never changes headers. A manage_options administrator may separately activate a complete reviewed candidate. The plugin emits one Content-Security-Policy header only on eligible logged-out public 2xx HTML/XHTML GET and HEAD responses. It excludes private/admin traffic, REST, AJAX, cron, feeds, previews, XML-RPC, CLI, redirects, errors, and non-HTML responses. Activation checks credential-free public GET and HEAD responses before and after the change. Status distinguishes locally stored state from exact publicly verified delivery. A failed check stays visible and does not silently deactivate or roll back. Administrators can verify again, deactivate, restore one prior state, or use the emergency bypass. Script Sentinel suppresses its header when PHP/WordPress exposes another enforced CSP. Headers added later by a host, proxy, cache, or CDN are outside PHP’s reliable view, so test on staging and inspect the final uncached response. Premium CSP Autopilot is an optional paid hosted service. Script Sentinel’s servers provide recurring verified-site scans, drift comparison, reduced CSP report aggregates, and staged rollout coordination. Payment covers those hosted operations; it does not unlock or extend local CSP controls. Enrollment is explicit. Safe drift can move through report-only observation, simulation, production probation, and exact commit or rollback; trust-expanding or unknown drift waits for approval. What “up to 10 pages” means The hosted free WordPress endpoint currently accepts at most one valid scan per canonical site during a rolling 60-minute period. Each scan can visit up to ten eligible public same-origin pages and may reach fewer. This service capacity and abuse-prevention limit applies only to hosted scans; it does not expire or disable local CSP controls. External service and data use This plugin uses the Script Sentinel service at https://script-sentinel.com/. Before an administrator starts a scan or Premium pairing, activation and ordinary administrator-page rendering send nothing to Script Sentinel. After Premium is connected, traffic-driven WP-Cron may start the separately disclosed agent synchronization during any request. When an administrator explicitly clicks Scan, the browser sends to https://script-sentinel.com/api/v1/wordpress/scan : The canonical public HTTPS site URL and public WordPress REST proof URL. A five-minute single-use proof and non-secret request identifier. Scan options and the requested 10-page maximum. Ordinary connection metadata such as IP address and user agent. The service returns the proof once to the public proof route, then visits public pages and resources. Their third-party hosts can observe scanner requests. The plugin sends no WordPress cookies, credentials, administrator email, authenticated content, user identity, or screenshots. Free mode stores the latest bounded result locally. If CSP deployment is used, WordPress also stores the active policy, checksum/fingerprint/change metadata, one rollback state, conflict status, short-lived HMAC-only delivery probes, and bounded delivery evidence in non-autoloaded options. Free deployment and verification do not contact Script Sentinel, and free mode performs no recurring service call. Premium pairing contact starts only after a WordPress administrator explicitly selects Connect Premium. Pairing sends the site URL, public WordPress site name/installation label, random installation ID, proof/challenge, profile/scopes, and plugin/protocol versions. PHP exchanges proof-bound machine credentials and stores them encrypted in non-autoloaded options. Automatic Autopilot CSP changes begin only after the authenticated Script Sentinel account explicitly approves and enrolls the installation. While connected, one serialized PHP agent normally contacts Script Sentinel every five minutes. It sends bounded installation/site identity, local CSP digests, revision, mode, watchdog/conflict state, command sequence, and acknowledgement, and receives at most one CSP command. Public responses never wait for this request. During Premium report-only or probation stages, eligible public browsers may send CSP violation reports to a random opaque Script Sentinel report endpoint. Normal network infrastructure may process connection metadata such as IP address and user agent for delivery and abuse prevention. Report bodies are reduced to bounded aggregates containing disposition/directive, normalized blocked source, redacted same-site path, original-policy digest, ambiguity, count, and timestamps. Script Sentinel retains those aggregates for at most 30 days and does not retain raw report bodies, raw policies, full URLs, queries/fragments, referrers, samples, cookies, authorization values, or client addresses in report aggregate rows. See the Privacy Policy for the complete service record. Premium sends no WordPress cookies, administrator credentials, private-page content, OAuth tokens, or Stripe IDs. Disconnect returns the committed CSP to local mode and removes credentials; use dashboard revoke if remote revocation cannot be confirmed. Uninstall removes local state without a remote request. Review these terms before using the service: Service: https://script-sentinel.com/ Pricing: https://script-sentinel.com/pricing Terms of Service: https://script-sentinel.com/terms Privacy Policy: https://script-sentinel.com/privacy Authorized-use and scanner limits: https://script-sentinel.com/about#scanner-limits-title Privacy See External service and data use above plus https://script-sentinel.com/privacy. Uninstall removes all local result, proof, deployment, verification, credential, agent, and scheduled-hook state without remote contact. Revoke a Premium installation in the dashboard if offline uninstall could not notify the service.