Descripción
EssentialHeaders is a focused WordPress plugin that attaches the HTTP security headers browsers expect, so protection is not left to chance or buried in server config.
Under Settings EssentialHeaders you get three tabs:
- Headers — overview of which headers are enabled and will be sent
- Settings — toggles and editable values for each header
- About — plugin info
Headers covered:
- Content-Security-Policy (CSP)
- Strict-Transport-Security (HSTS)
- X-Frame-Options
- X-Content-Type-Options
- Referrer-Policy
- Permissions-Policy
Safer headers ship enabled with sensible defaults. CSP starts off so you can adopt it deliberately. Headers apply to public site responses (pages, feeds, and the login screen)—not wp-admin, AJAX, REST, GraphQL, or XML-RPC. HSTS is only sent over HTTPS. Default HSTS uses max-age only; add includeSubDomains yourself when every subdomain is ready.
Instalación
- Upload the
essentialheadersfolder to the/wp-content/plugins/directory. - Activate the plugin through the Plugins menu in WordPress.
- Open Settings EssentialHeaders to review and configure headers.
FAQ
-
Will this break my site?
-
The default set is conservative. Content-Security-Policy is off by default because a strict CSP can block scripts or styles your theme needs. Enable CSP when you are ready to tune it.
-
Does HSTS work on HTTP?
-
No. Strict-Transport-Security is only sent when the visitor reaches the site over HTTPS.
-
Does the login screen get these headers?
-
Yes. The login screen is treated as a public response. wp-admin, AJAX, REST, GraphQL, and XML-RPC are excluded so dashboards and APIs are not broken by a strict CSP.
-
Does this change site content?
-
No. The plugin only stores its own options and adds HTTP response headers on public responses.
Reseñas
No hay valoraciones para este plugin.
Colaboradores y desarrolladores
«EssentialHeaders» es un software de código abierto. Las siguientes personas han colaborado con este plugin.
ColaboradoresTraduce «EssentialHeaders» a tu idioma.
¿Interesado en el desarrollo?
Revisa el código , echa un vistazo al repositorio SVN o suscríbete al registro de desarrollo por RSS.
Registro de cambios
1.0.1
- Fix: always send security headers on front-end HTML even when the request Accept header prefers JSON. Skipping those requests let page caches store header-less responses and broke scanner results after cache warm-up.
1.0.0
- Initial release.
