Terms of Service for Script Sentinel

Effective:

These Terms govern use of the Script Sentinel website, public Content Security Policy scanner, browser extensions, WordPress plugin, accounts, monitoring, and Premium services. By using a service, creating an account, or connecting a WordPress installation, you agree to these Terms and our Privacy Policy.

1. Your authority and authorized use

You may scan, monitor, connect, or manage only a website that you own or are expressly authorized to test. You are responsible for obtaining any consent required from the website owner, hosting provider, users, or other affected party. Script Sentinel is not permission to test someone else's systems. Additional operational limits appear in our authorized-use guidance.

2. The service

Script Sentinel observes bounded public browser activity and produces CSP candidates, reports, exports, and monitoring evidence. Free features may be used without a Premium account. Premium features may include verified-site monitoring, drift history, alerts, WordPress pairing, and automated CSP rollout assistance. Features and limits shown in the product or on the Pricing page form part of the service description for the plan in use.

Scanner output is a candidate based on reached pages and states. It is not a complete inventory, penetration test, certification, legal-compliance determination, or guarantee that a policy is safe to enforce.

3. WordPress and CSP Autopilot

The WordPress plugin is GPL-licensed software that can use Script Sentinel's hosted service. Free scans and local CSP deployment remain administrator-controlled. Premium CSP Autopilot begins only after a WordPress administrator explicitly enrolls the installation and an authorized Script Sentinel account approves the exact pairing and Autopilot profile.

Once enrolled, Autopilot may issue bounded commands that move an exact candidate through report-only observation, enforcing simulation, production probation, commit, or rollback. Trust-expanding or otherwise unprovable changes require exact-candidate approval. The plugin's local watchdog is designed to restore the previous committed state when a rollout expires or fails, but no automated safeguard can eliminate every hosting, cache, proxy, theme, plugin, or application-state risk.

CSP enforcement can block site functionality. You remain responsible for choosing appropriate sites, keeping independent file and hosting access, testing important logged-in and conditional flows, maintaining backups, and being able to purge WordPress, host, proxy, and CDN caches. You may disconnect Autopilot or uninstall the plugin, subject to the local state and recovery behavior described in the plugin.

4. Accounts and credentials

You must provide accurate account information, protect your sign-in and WordPress administrator access, and promptly revoke or disconnect credentials you believe are compromised. You are responsible for activity authorized through your account or installation unless applicable law provides otherwise. Do not publish access tokens, refresh tokens, pairing codes, proof values, report endpoint tokens, or recovery material.

5. Paid plans

Paid subscriptions are billed through the checkout provider at the price, interval, taxes, and plan limits displayed before purchase. Unless the checkout states otherwise, subscriptions renew automatically until canceled. Cancellation stops future renewal but does not retroactively undo a completed billing period. Mandatory consumer rights and any checkout-specific refund terms continue to apply.

6. Acceptable use

You must not use Script Sentinel to:

  • scan or access systems without authorization;
  • evade rate limits, proof checks, access controls, or service safeguards;
  • distribute malware, exploit vulnerabilities, disrupt service, or harm another person;
  • submit secrets, private-network targets, unlawful material, or unnecessary personal data;
  • misrepresent scanner output as a certification or guaranteed security result; or
  • resell or automate access in a way that materially burdens the service without written permission.

7. Data and privacy

Our Privacy Policy explains what the scanner, extensions, WordPress plugin, Premium agent, browser CSP report endpoints, account system, billing provider, and email provider process and retain. You are responsible for giving your own users any notice required for a CSP reporting endpoint or other processing you enable on your site.

8. Software and content

The WordPress plugin and other published open-source components remain governed by their included licenses. These Terms do not replace those licenses. Script Sentinel retains rights in the hosted service, website, branding, and non-open-source content. You retain rights in your sites and data and grant Script Sentinel only the permission reasonably needed to process them to provide, secure, and support the service.

9. Security-tool limitations

CSP is defense in depth, not a complete security control. Public scans can miss authenticated, personalized, consent-gated, geographic, time-dependent, ecommerce, membership, lazy-loaded, and user-triggered behavior. Browser violation reports can be missing, delayed, duplicated, noisy, or caused by unrelated policies. You must review results and test representative staging and production behavior appropriate to your site.

10. Availability and changes

We may maintain, secure, change, limit, or discontinue service features. We will use reasonable efforts to avoid unnecessary disruption and to communicate material changes when appropriate. Service status and dependency failures may delay scans, monitoring, messages, or WordPress commands.

11. Disclaimers and liability

To the extent permitted by law, the service is provided "as is" and "as available," without warranties that scans are complete, findings are error-free, or a generated or deployed policy will preserve every site flow. To the extent permitted by law, Script Sentinel is not liable for indirect, incidental, special, consequential, or punitive damages, loss of data, lost revenue, or loss caused by unauthorized use, unavailable dependencies, or a policy you deploy. Nothing in these Terms excludes liability or rights that cannot legally be excluded.

12. Suspension and termination

You may stop using free services, cancel a paid plan, remove monitored sites, revoke a WordPress installation, or request account deletion through the available controls. We may suspend or terminate access when reasonably necessary to address abuse, security risk, nonpayment, legal requirements, or a material breach of these Terms. Provisions that by their nature should survive termination, including license, payment, disclaimer, and limitation provisions, continue to apply.

13. General terms

If part of these Terms is unenforceable, the remaining terms continue to apply. A failure to enforce a term is not a waiver. You may not transfer your account or these Terms in a way that compromises another site's consent or credentials. We may update these Terms by publishing a revised effective date; material changes apply prospectively unless law requires otherwise.

14. Contact

Questions about these Terms can be sent through the Script Sentinel contact page. Security vulnerabilities should use the security-report channel.