SplatDev.Umbraco.Plugins.Security 2.0.5

dotnet add package SplatDev.Umbraco.Plugins.Security --version 2.0.5
                    
NuGet\Install-Package SplatDev.Umbraco.Plugins.Security -Version 2.0.5
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="SplatDev.Umbraco.Plugins.Security" Version="2.0.5" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="SplatDev.Umbraco.Plugins.Security" Version="2.0.5" />
                    
Directory.Packages.props
<PackageReference Include="SplatDev.Umbraco.Plugins.Security" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add SplatDev.Umbraco.Plugins.Security --version 2.0.5
                    
#r "nuget: SplatDev.Umbraco.Plugins.Security, 2.0.5"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package SplatDev.Umbraco.Plugins.Security@2.0.5
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=SplatDev.Umbraco.Plugins.Security&version=2.0.5
                    
Install as a Cake Addin
#tool nuget:?package=SplatDev.Umbraco.Plugins.Security&version=2.0.5
                    
Install as a Cake Tool

Security

Umbraco security headers plugin — adds Content-Security-Policy, HSTS, X-Frame-Options, and other HTTP security headers via middleware, plus ASP.NET Data Protection configuration.

NuGet

Compatibility

Umbraco .NET Package Version
13.x 8.0 2.0.5
17.x 10.0 2.0.5

Installation

dotnet add package SplatDev.Umbraco.Plugins.Security

Quick Start

No registration call is needed. The package ships Umbraco composers, so the AddComposers() already in the default Program.cs picks the plugin up as soon as the package is referenced.

Configuration

Add to appsettings.json:

{
  "CSP": {
    "default-src": "'self'",
    "script-src": "'self' 'unsafe-inline'",
    "font-src": "'self'",
    "frame-src": "'self'",
    "frame-ancestors": "'self'",
    "image-src": "'self' data:",
    "connection-src": "'self'"
  },
  "DataProtection": {
    "Enabled": true,
    "PathToPersistKeys": "/var/data/keys",
    "ApplicationName": "MyUmbracoApp",
    "PathToCertificate": null,
    "Password": null
  }
}

Headers Applied

Header Value Configuration
Content-Security-Policy Configured via CSP:* keys Customizable per directive
Strict-Transport-Security max-age=604800 (7 days) Hardcoded
X-Frame-Options SAMEORIGIN Default
X-Content-Type-Options nosniff Always set
Referrer-Policy no-referrer-when-downgrade Default

Known Limitations

  • CSP is entirely disabled for all /umbraco paths (backoffice pages are excluded from policy enforcement)
  • HSTS max-age is hardcoded to 7 days with no configuration option; non-production environments skip HSTS entirely
  • Uses both NWebsec.AspNetCore.Middleware and Joonasw.SecurityHeaders for different headers, which is a maintenance concern
  • Windows Data Protection key path is hardcoded to C:\temp

Changelog

2.0.5 — 2026-08-25

Documentation only, no code change. The README's Quick Start told you to call a registration method that does not exist in this package — following it produced a compile error on the first build. There is nothing to register: the package ships Umbraco composers and the AddComposers() already in the default Program.cs finds it. The Compatibility table also now shows the version actually being shipped instead of the one it was written at.

2.0.4 — 2026-08-24

Removes a dashboard screenshot that showed an error toast. It was captured against a site where this plugin's API was unreachable, so it advertised a broken dashboard. No screenshot is better than a misleading one; a replacement will be taken against a working install.

2.0.3 — 2026-08-24

Package metadata only: the listing now carries an icon and search tags, and the project and repository links point at the organisation that actually hosts this code. No code changes.

2.0.2 — 2026-08-24

This package now keeps a changelog. Earlier releases predate it and are not reconstructed here — consult the repository history for those. From this version on, every release records what changed for someone using it.

License

MIT © SplatDev

Architecture

This is a headless middleware plugin — no backoffice dashboard, property editors, or UI components. It operates as HTTP middleware (security headers + Data Protection configuration), registered via DI composition.

Product Compatible and additional computed target framework versions.
.NET net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
2.0.5 24 8/25/2026