Skip to content

Content-Security-Policy and Drupal 11

Ready

The latest stable release, 2.2.4, declares a core version requirement of ^10.2 || ^11, which covers Drupal 11.

Configure a Content-Security-Policy header for your Drupal site to detect and mitigate the risk of Cross Site Scripting (XSS) and other vulnerabilities.

Key facts

Project
csp
Latest stable with Drupal 11 support
2.2.4 (28 Apr 2026)
Core version requirement
^10.2 || ^11
Maintenance status
Actively maintained
Reported installs
24,974
Last synced from drupal.org
21 Sept 2026

Every field above comes from the drupal.org API. The Drupal 11 status is derived from the core version requirement across this project's releases.

Source: drupal.org/project/csp