mod_pagespeed 2.1 parses and rewrites HTML responses on your own server, as a stream. We plan
to open that pipeline to signed transform packs: declarative rules for compliance, privacy and
SEO jobs that often need a CDN feature or a JavaScript agent today. Tell us which pack you
need.
Status
None of these packs ships today. The interceptor they would run on does. Early access means
you hear first when there is a build to try, and your input shapes it.
Payment-page script integrity
Inventory every script on checkout and payment pages, add integrity hashes and per-response nonces, and enforce an allowlist, all in the HTML stream. The aim is evidence that helps with PCI DSS 4.0 requirements 6.4.3 and 11.6.1.
Third-party freeze and front-end SBOM
The pack would pin every external script to a reviewed copy served from your own domain, hold upstream changes until someone approves them, and export a CycloneDX bill of materials of the front end.
Consent enforcement at the origin
The pack would keep third-party tags inert until the consent cookie grants them, and set Consent Mode defaults at the origin before page scripts run. Its inventory would list the third parties that actually fire.
Canonicals, hreflang, titles and structured data fixed at serve time, with no CMS change and no CDN. The pack would apply rules to the HTML stream in the interceptor, so a fix reaches every page the rule matches.
Mask leaked stack traces and personal data, strip version tells and add missing security headers in the response. For sites on software that no longer gets updates, the response is the layer you can still change.
Write your own
Packs are planned as declarative, signed rules, so your own rules would run under the same signature check. Tell us if you would write custom filters.
Request a pack
Something else the pipeline should do for your site? Describe the job.