ModKor CSP for Magento 2 & Hyva

Stop fighting Content Security Policy. ModKor CSP watches what your store loads, recognises the vendor, and turns every blocked script into a one-click whitelist fix - with risk scoring and a safe report-only to enforce workflow. Hyva-friendly, multi-store, no XML editing.
Email to a Friend
SKU
ModKorCsp
$129.00
Requirement
  • Magento 2.4.8+ (Community Edition)
  • Hyva 1.4.6+ (License required)
  • Php 8.4+
  • Node 20+
12 Month Support Included
Free Installation Included

Stop fighting Content Security Policy

Magento ships CSP in report-only mode and leaves you to hand-edit XML whitelist files every time a payment provider, analytics tag or chat widget gets blocked. ModKor CSP watches what your store actually loads, recognises the vendor, and offers it to you as a one-click fix.

Why it beats the alternatives

  • Recognises the vendor. A blocked PayPal script shows up as “PayPal — Recommended”, not a cryptic URL.
  • One click adds every host a vendor needs across script-src, frame-src, connect-src and more — not one URL at a time.
  • Risk scoring — safe known vendors are green, unknown hosts amber, wildcards/inline red.
  • Auto-learn mode — recognised vendors whitelist themselves; unknown hosts still wait for your review.
  • Apply baseline — pre-seed Google, PayPal, reCaptcha & Cloudflare so a fresh store is covered before any traffic.
  • Report-only → Enforce, safely, from one dashboard.

Built-in vendor catalog (29 services)

PayPal, Stripe, Braintree, Klarna, Afterpay, Adyen, Google Analytics / Tag Manager / Ads / reCaptcha / Maps / Fonts, YouTube, Vimeo, Cloudflare Turnstile & Web Analytics, hCaptcha, Meta Pixel, TikTok, Klaviyo, Mailchimp, Hotjar, Microsoft Clarity, Yotpo, Trustpilot, Tawk.to, Zendesk, Intercom and Sentry — and it grows every release.

What you get

  • Modern React dashboard (multi-store aware) with live preview
  • Violation log + vendor-aware suggestion engine
  • Manual add: known-service picker or any custom host/directive
  • Inline-hash support as a safer alternative to unsafe-inline
  • Hyva-friendly, CSP-self-compliant, secret-free

Compatibility

Magento Open Source & Adobe Commerce 2.4.x · PHP 8.1–8.4 · Luma & Hyva. Built on Magento’s own Magento_Csp so it composes with the platform rather than fighting it.