PluginScout

No unsafe-inline — WordPress Multisite Plugin

by Giuseppe · WordPress.org page · Website

v1.3.0 Tested up to WP 6.9.7 PHP 7.4+

No unsafe-inline has 200+ active installs on WordPress.org and 12,082 downloads all time. We have tracked it since September 4, 2026; download trends appear after 30 days of data. The last update was on December 4, 2025, tested up to WordPress 6.9.7.

No unsafe-inline at a glance

Active installs
200+
Total downloads
12,082
Downloads, last 30 days
available after 30 days of tracking
30-day growth
tracking since September 4, 2026

Is No unsafe-inline well maintained?

Support threads resolved
0 of 1
recent threads on the WordPress.org support forum
WordPress compatibility
Behind
tested up to WordPress 6.9.7, not yet with the current 7.1

Features

The feature list from the plugin's own readme on WordPress.org, trimmed to the essentials.

  • During a capture phase, it detects the scripts, styles and other embedded content present in the pages of your site and stores them in the database
  • Then you have to whitelist these contents from plugin admin
  • The plugin uses machine learning to cluster inline scripts trying to aggregate scripts generated by the same server side (PHP) code. So, you can authorize one…
  • You can choose to use hashes to authorize external scripts (and the plugin will allow you to include Subresource Integrity in your <script> and <link>)
  • You can use hashes or nonces to authorize inline scripts
  • You can ask the plugin to refactor your page to not use event attributes (converted in a inline script) and inline styles (converted in an internal CSS)
  • You can set one or more violations’ report endpoints

No unsafe-inline reviews and ratings

5 reviews on WordPress.org, with the most recent ones as their authors posted them.

5.0 out of 5

5 reviews

5★
5
4★
0
3★
0
2★
0
1★
0
  • Exceeds Expectations

    This plugin has a learning curve. And it demands patience. But the results exceed expectations. I used this plugin on a local server. I aimed to find Gutenberg Inline styles in (rendered) HTML. This plugin found the inline styles and several style attributes.

    hohumtiddleypom
  • Excellent plugin

    Works like it says on the box. Make sure you have the right PHP modules installed. Thanks for building this!

    mdbraber
  • Extremely useful plugin

    Not everything went smoothly, I had to abandon the Clearfy plugin and tinker with the settings, but it was worth it. All СSP headers passed the evaluator-test successfully.

    feofanidze
  • The only plugin that can build a strict CSP

    I've tried countless plugins for creating CSP policies, but none of them let you create strong policies that could actually mitigate XSS attacks. This plugin is pretty young and is made by a solo developer, naturally there are some rough edges for such a plugin. But these problems should go away with time.

    Anonymous User
  • Absolutely the best plugin for strict csp

    The only possible solution for those who want to adopt a stricted csp. I have installed dozens of plugins for the management of the CSP, but THERE IS NO OTHER FREE PLUGIN that allows to use scripts and CSS online without disabling the protection against XSS vulnerabilities. All others disable the protection by adding the "unsafe-inline" directive. The solution adopted by this plugin is the only intelligent one: it removes styles and scripts in line, putting them in external files (allowed by stricted policy). Furthermore, the creator was very kind, thorough and helpful. Although perhaps a bit immature, I absolutely recommend this plugin, to try! Gianni

    gianni65

Where No unsafe-inline ranks on WordPress.org

The rankings we track that No unsafe-inline appears in, and how its position changed over 30 days.

Ranking WordPress.org placement Position 30 days
Best Multisite Plugins #27 by tag, not in search #52

Details

No unsafe-inline helps you to build a Content Security Policy avoiding to use 'unsafe-inline' and 'unsafe-hashes'.

The full description, screenshots and every review live on the WordPress.org page.

Rankings No unsafe-inline competes in

Tags

  • content security policy
  • csp
  • multisite
  • security
  • unsafe-inline

More from Giuseppe

Version
1.3.0
Last updated
Dec 4, 2025
First published
Mar 25, 2022
Requires WordPress
5.9
Tested up to
6.9.7
Requires PHP
7.4
Pricing
Free on WordPress.org

No unsafe-inline FAQ

What does No unsafe-inline do?

According to its WordPress.org readme, No unsafe-inline offers During a capture phase, it detects the scripts, styles and other embedded content present in the pages of your site and stores them in the database, Then you have to whitelist these contents from plugin admin, The plugin uses machine learning to cluster inline scripts trying to aggregate scripts generated by the same server side (PHP) code. So, you can authorize one, You can choose to use hashes to authorize external scripts (and the plugin will allow you to include Subresource Integrity in your <script> and <link>) and You can use hashes or nonces to authorize inline scripts.

How many active installs does No unsafe-inline have?

WordPress.org reports 200+ active installs for No unsafe-inline as of September 7, 2026.

Is No unsafe-inline still maintained?

Yes. The last release was on December 4, 2025 and it is tested up to WordPress 6.9.7.

Does No unsafe-inline have good support?

On the WordPress.org forum, 0 of 1 recent support threads for No unsafe-inline are marked resolved. That is the developer's free support; a paid version usually comes with its own channel.

Is No unsafe-inline free?

No unsafe-inline is free to install from WordPress.org. Many plugins also sell a paid version or add-ons.

Where does No unsafe-inline rank among Multisite Plugins?

No unsafe-inline is #52 in the WordPress.org Multisite Plugins ranking.