Title: Beplus Security Headers &amp; Script Auditor
Author: rimbeplus
Published: <strong>2026 年 8 月 19 日</strong>
Last modified: 2026 年 8 月 19 日

---

搜尋外掛

![](https://ps.w.org/beplus-security-headers-script-auditor/assets/banner-772x250.
png?rev=3654344)

![](https://ps.w.org/beplus-security-headers-script-auditor/assets/icon-256x256.
png?rev=3654344)

# Beplus Security Headers & Script Auditor

 由 [rimbeplus](https://profiles.wordpress.org/rimbeplus/) 開發

[下載](https://downloads.wordpress.org/plugin/beplus-security-headers-script-auditor.1.0.0.zip)

 * [詳細資料](https://tw.wordpress.org/plugins/beplus-security-headers-script-auditor/#description)
 * [使用者評論](https://tw.wordpress.org/plugins/beplus-security-headers-script-auditor/#reviews)
 *  [安裝方式](https://tw.wordpress.org/plugins/beplus-security-headers-script-auditor/#installation)
 * [開發資訊](https://tw.wordpress.org/plugins/beplus-security-headers-script-auditor/#developers)

 [技術支援](https://wordpress.org/support/plugin/beplus-security-headers-script-auditor/)

## 外掛說明

Beplus Security Headers & Script Auditor gives WordPress site owners three things
in one screen:

 1. **Security header toggles** — enable X-Frame-Options, X-Content-Type-Options, Referrer-
    Policy, Strict-Transport-Security, Permissions-Policy, Content-Security-Policy (
    with an optional report-only mode), and the legacy X-XSS-Protection header, each
    with sensible defaults.
 2. **A scanner** — fetches your homepage, or optionally your whole site (up to 200
    of your most recently published posts/pages), and lists every external script, 
    stylesheet, image, iframe, and form target it finds, plus a count of inline scripts/
    styles.
 3. **Recommendations you control** — every finding is listed as a checkbox row; uncheck
    anything you don’t want, and the Content-Security-Policy preview updates live. 
    Apply the checked rows to the CSP field with one click, review it, then press Save.
    Nothing is ever sent automatically.

There’s also a repeatable table for adding any other custom response header your
site needs.

#### Why use this plugin

 * No external service calls, tracking, or phone-home behaviour — the scan only 
   requests pages on your own site.
 * Every setting is sanitized on save, and header values are stripped of line breaks
   to prevent HTTP header injection.
 * Sensible, conservative defaults: only X-Frame-Options, X-Content-Type-Options,
   and Referrer-Policy are enabled out of the box. HSTS, Permissions-Policy, CSP,
   and X-XSS-Protection are opt-in since they can affect how your site behaves and
   should be reviewed first.

## 螢幕擷圖

[⌊The Headers tab, where each security header can be toggled and configured.⌉⌊The
Headers tab, where each security header can be toggled and configured.⌉[

The Headers tab, where each security header can be toggled and configured.

[⌊The Scanner tab, showing detected external resources as a checklist and a live
Content-Security-Policy preview.⌉⌊The Scanner tab, showing detected external resources
as a checklist and a live Content-Security-Policy preview.⌉[

The Scanner tab, showing detected external resources as a checklist and a live Content-
Security-Policy preview.

## 安裝方式

 1. Upload the plugin files to the `/wp-content/plugins/beplus-security-headers-script-
    auditor` directory, or install the plugin through the WordPress plugins screen 
    directly.
 2. Activate the plugin through the ‘Plugins’ screen in WordPress.
 3. Go to the “Security Headers” menu item (in the main admin sidebar) to review the
    default header configuration.
 4. Open the Scanner tab and click “Run Scan” (optionally ticking “Scan entire site”
    first) to see what external resources your site loads, uncheck anything you don’t
    want, then apply the checked rows to the Content-Security-Policy field.
 5. Click “Save Changes” to apply your configuration.

## 常見問題集

### Will this break my site if I enable everything at once?

It can, especially Content-Security-Policy. Start with the scanner recommendations,
use “Report-only mode” for CSP first to observe without blocking anything, and only
switch to enforcing mode once you’ve confirmed the policy covers everything your
site actually loads.

### Does the scanner send my data anywhere?

No. It performs normal HTTP requests from your own server to pages on your own site,
using the built-in WordPress HTTP API. Nothing is sent to any third party.

### Does this replace a full security audit?

No. Even the whole-site option only scans your homepage plus your most recently 
published posts/pages (capped at 200) and is meant as a starting point for building
a Content-Security-Policy, not a substitute for a complete security review of your
site.

## 使用者評論

這個外掛目前沒有任何使用者評論。

## 參與者及開發者

以下人員參與了開源軟體〈Beplus Security Headers & Script Auditor〉的開發相關工作。

參與者

 *   [ rimbeplus ](https://profiles.wordpress.org/rimbeplus/)

[將〈Beplus Security Headers & Script Auditor〉外掛本地化為台灣繁體中文版](https://translate.wordpress.org/projects/wp-plugins/beplus-security-headers-script-auditor)

### 對開發相關資訊感興趣？

任何人均可[瀏覽程式碼](https://plugins.trac.wordpress.org/browser/beplus-security-headers-script-auditor/)、
查看 [SVN 存放庫](https://plugins.svn.wordpress.org/beplus-security-headers-script-auditor/)，
或透過 [RSS](https://plugins.trac.wordpress.org/log/beplus-security-headers-script-auditor/?limit=100&mode=stop_on_copy&format=rss)
訂閱[開發記錄](https://plugins.trac.wordpress.org/log/beplus-security-headers-script-auditor/)。

## 變更記錄

#### 1.0.0

 * Initial release: security header toggles, homepage/whole-site scanner with a 
   pick-and-choose CSP checklist, and custom header repeater.

## 中繼資料

 *  版本 **1.0.0**
 *  最後更新 **3 週前**
 *  啟用安裝數 **少於 10 次**
 *  WordPress 版本需求 ** 6.0 或更新版本 **
 *  已測試相容的 WordPress 版本 **7.1**
 *  PHP 版本需求 ** 7.4 或更新版本 **
 *  語言
 * [English (US)](https://wordpress.org/plugins/beplus-security-headers-script-auditor/)
 * 標籤:
 * [content security policy](https://tw.wordpress.org/plugins/tags/content-security-policy/)
   [csp](https://tw.wordpress.org/plugins/tags/csp/)[headers](https://tw.wordpress.org/plugins/tags/headers/)
   [http-headers](https://tw.wordpress.org/plugins/tags/http-headers/)[security](https://tw.wordpress.org/plugins/tags/security/)
 *  [進階檢視](https://tw.wordpress.org/plugins/beplus-security-headers-script-auditor/advanced/)

## 評分

這個項目尚無任何評論記錄。

[撰寫評分](https://wordpress.org/support/plugin/beplus-security-headers-script-auditor/reviews/#new-post)

[查看全部使用者評論](https://wordpress.org/support/plugin/beplus-security-headers-script-auditor/reviews/)

## 參與者

 *   [ rimbeplus ](https://profiles.wordpress.org/rimbeplus/)

## 技術支援

使用者可在技術支援論壇提出意見反應或使用問題。

 [檢視技術支援論壇](https://wordpress.org/support/plugin/beplus-security-headers-script-auditor/)