Ghost
Open-source publishing with built-in newsletters and paid subscriptions, run by a nonprofit with no investors.
What it does
| Primary use case | Open-source publishing platform for content creators with newsletter and subscription capabilities |
|---|---|
| Setup speed | Requires manual configuration and content setup as a traditional publishing platform |
| Code requirements | Open-source platform that can be customized with code but also offers hosted no-code options |
| Business model | Operated by a nonprofit organization with no investors, emphasizing open-source values |
Pick Ghost if
- You are building a content publication with articles, newsletters, and subscriber engagement
- You value open-source software and nonprofit governance over commercial platforms
- You need built-in newsletter and paid subscription features for audience monetization
- You want full control over your publishing platform with the option to self-host
- You're building a content publication, blog, or online magazine
- You want open-source software you can self-host or customize
Compare
Security headers: A, 90 out of 100
Number 9 of 95 in the ranking. Missing 2 of the 9 headers we check.
Meets the B minimum (70/100) in our RFP clause.
With these headers missing, ghost.org is more exposed to clickjacking.
Missing 2
-
Cross-Origin-Opener-Policy 0 of 5
Cuts the link between the product's window and windows opened by, or opening, other sites.
Without it: A page that opens the product keeps a handle on its window and can later redirect it to a look-alike sign-in or payment page (tab-nabbing) while the user thinks they are still on the real site. It is also part of the isolation browsers need to defend against Spectre-style attacks.
-
Cross-Origin-Resource-Policy 0 of 5
Tells browsers which sites may load this site's resources.
Without it: Other sites can pull the product's responses into their own pages, which makes side-channel leaks of what a signed-in user can see easier.
Sent 7
-
Content-Security-Policy 25 of 25
default-src 'self' customer-cubrih08bflu3z2b.cloudflarestream.com pages.churnbuster.io ghbtns.com help.ghost.io resources.ghost.io tutorials.ghost.io changelog.ghost.io t.firstpromoter.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: cdn.jsdelivr.net https://cdn.firstpromoter.com proxy-assets.churnbuster.io https://static.ads-twitter.com embed.ghoststatus.org https://www.dubcdn.com/analytics/script.js ingest.promptwatch.com https://esm.sh https://vjs.zencdn.net https://analytics.ahrefs.com; style-src 'self' 'unsafe-inline' proxy-assets.churnbuster.io https://vjs.zencdn.net; font-src 'self' data: rsms.me/inter/font-files/; img-src 'self' 'unsafe-inline' data: supapjpiqdfzuaordcdx.supabase.co/storage/ analytics.twitter.com https://t.co https://dubassets.com https://*.cloudflarestream.com https://*.laravel.cloud; media-src 'self' blob: https://*.cloudflarestream.com; connect-src 'self' analytics.twitter.com https://ads-api.twitter.com/ t.firstpromoter.com https://api.dub.co/track/click ingest.promptwatch.com https://ingesteer.services-prod.nsvcs.net https://*.cloudflarestream.com https://analytics.ahrefs.com; worker-src 'self' blob:; frame-src 'self' https://app.netlify.com https://ghbtns.com https://pages.churnbuster.io;
-
Strict-Transport-Security 20 of 20
max-age=31536000
-
X-Content-Type-Options 10 of 10
nosniff
-
Frame protection 10 of 10
SAMEORIGIN
-
Referrer-Policy 10 of 10
no-referrer-when-downgrade
-
Permissions-Policy 10 of 10
accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=()
-
No version disclosure 5 of 5
server: Netlify