ModKor CSP for Magento 2 & Hyva
- SKU
- ModKorCsp
- Magento 2.4.8+ (Community Edition)
- Hyva 1.4.6+ (License required)
- Php 8.4+
- Node 20+
Stop fighting Content Security Policy
Magento ships CSP in report-only mode and leaves you to hand-edit XML whitelist files every time a payment provider, analytics tag or chat widget gets blocked. ModKor CSP watches what your store actually loads, recognises the vendor, and offers it to you as a one-click fix.
Why it beats the alternatives
- Recognises the vendor. A blocked PayPal script shows up as “PayPal — Recommended”, not a cryptic URL.
- One click adds every host a vendor needs across script-src, frame-src, connect-src and more — not one URL at a time.
- Risk scoring — safe known vendors are green, unknown hosts amber, wildcards/inline red.
- Auto-learn mode — recognised vendors whitelist themselves; unknown hosts still wait for your review.
- Apply baseline — pre-seed Google, PayPal, reCaptcha & Cloudflare so a fresh store is covered before any traffic.
- Report-only → Enforce, safely, from one dashboard.
Built-in vendor catalog (29 services)
PayPal, Stripe, Braintree, Klarna, Afterpay, Adyen, Google Analytics / Tag Manager / Ads / reCaptcha / Maps / Fonts, YouTube, Vimeo, Cloudflare Turnstile & Web Analytics, hCaptcha, Meta Pixel, TikTok, Klaviyo, Mailchimp, Hotjar, Microsoft Clarity, Yotpo, Trustpilot, Tawk.to, Zendesk, Intercom and Sentry — and it grows every release.
What you get
- Modern React dashboard (multi-store aware) with live preview
- Violation log + vendor-aware suggestion engine
- Manual add: known-service picker or any custom host/directive
- Inline-hash support as a safer alternative to unsafe-inline
- Hyva-friendly, CSP-self-compliant, secret-free
Compatibility
Magento Open Source & Adobe Commerce 2.4.x · PHP 8.1–8.4 · Luma & Hyva. Built on Magento’s own Magento_Csp so it composes with the platform rather than fighting it.