CSP Whitelist (SISL fork)
Manage your Magento CSP whitelist from the admin panel, no deploy. Revived, runs on 2.4.9.
Magento 2.4 ships Content Security Policy, but the whitelist of trusted hosts (analytics, payment gateways, chat, CDNs) lives in csp_whitelist.xml — every change needs a commit, a deploy and a developer. This module moves the whitelist into the admin panel.
Add a blocked host in Stores → Configuration → Cti → CSP Whitelist, save, flush cache — no code changes. From our scan: about half of Magento stores send no CSP header at all.
The CTI Digital original was abandoned in 2021 (composer.json had no requirements). SISL fork: fixed requirements, runs on Magento 2.4.9 / PHP 8.4. Free, open source.