EssentialHeaders

外掛說明

EssentialHeaders is a focused WordPress plugin that attaches the HTTP security headers browsers expect, so protection is not left to chance or buried in server config.

Under Settings EssentialHeaders you get three tabs:

  • Headers — overview of which headers are enabled and will be sent
  • Settings — toggles and editable values for each header
  • About — plugin info

Headers covered:

  • Content-Security-Policy (CSP)
  • Strict-Transport-Security (HSTS)
  • X-Frame-Options
  • X-Content-Type-Options
  • Referrer-Policy
  • Permissions-Policy

Safer headers ship enabled with sensible defaults. CSP starts off so you can adopt it deliberately. Headers apply to public site responses (pages, feeds, and the login screen)—not wp-admin, AJAX, REST, GraphQL, or XML-RPC. HSTS is only sent over HTTPS. Default HSTS uses max-age only; add includeSubDomains yourself when every subdomain is ready.

安裝方式

  1. Upload the essentialheaders folder to the /wp-content/plugins/ directory.
  2. Activate the plugin through the Plugins menu in WordPress.
  3. Open Settings EssentialHeaders to review and configure headers.

常見問題集

Will this break my site?

The default set is conservative. Content-Security-Policy is off by default because a strict CSP can block scripts or styles your theme needs. Enable CSP when you are ready to tune it.

Does HSTS work on HTTP?

No. Strict-Transport-Security is only sent when the visitor reaches the site over HTTPS.

Does the login screen get these headers?

Yes. The login screen is treated as a public response. wp-admin, AJAX, REST, GraphQL, and XML-RPC are excluded so dashboards and APIs are not broken by a strict CSP.

Does this change site content?

No. The plugin only stores its own options and adds HTTP response headers on public responses.

使用者評論

這個外掛目前沒有任何使用者評論。

參與者及開發者

以下人員參與了開源軟體〈EssentialHeaders〉的開發相關工作。

參與者

將〈EssentialHeaders〉外掛本地化為台灣繁體中文版

對開發相關資訊感興趣?

任何人均可瀏覽程式碼、查看 SVN 存放庫,或透過 RSS 訂閱開發記錄

變更記錄

1.0.1

  • Fix: always send security headers on front-end HTML even when the request Accept header prefers JSON. Skipping those requests let page caches store header-less responses and broke scanner results after cache warm-up.

1.0.0

  • Initial release.