這個外掛並未在最新的 3 個 WordPress 主要版本上進行測試。開發者可能不再對這個外掛進行維護或提供技術支援,並可能會與更新版本的 WordPress 產生使用上的相容性問題。

HTTPS Mixed Content Detector

外掛說明

When deploying a TLS enabled website, you must ensure that all content loaded on the site is loaded from secure origin.
If your content is loaded from an insecure source, the security of your whole site is compromised and modern browsers
will downgrade your website’s security rating.

The HTTPS Mixed Content Detector plugin attempts to identify sources of mixed content warnings. The plugin will examine
content loaded from the site when admins are viewing the site. Any content that violates the policy of loading content
that originates from “https:” resources will trigger an error and that resource will be logged. Viewing the log will
allow you to examine the site for any warnings and remove them before they cause problems for your website.

螢幕擷圖

  • Content Security Policy reports are collected in the Content Security Policy Reports list table.
  • Information about Content Security Policy reports is available via WP CLI.

安裝方式

This section describes how to install the plugin and get it working.

  1. Upload https-mixed-content-detector to the /wp-content/plugins/ directory
  2. Activate the plugin through the ‘Plugins’ menu in WordPress
  3. Browse your site as an admin
  4. View the reports listed in the “Content Security Policy Reports” page in the admin
  5. Delete each violation report log as you fix it
  6. Rinse and repeat until your site is free of violation reports

使用者評論

2020 年 10 月 7 日
This plugin immediately detected that the header image was causing trouble, while other SSL fixing plugins couldn't fix the problem
2016 年 12 月 6 日
It works as advertised. Unfortunately, I do not know how fix the error since the location is unknown.
閱讀全部 6 則使用者評論

參與者及開發者

以下人員參與了開源軟體〈HTTPS Mixed Content Detector〉的開發相關工作。

參與者

將〈HTTPS Mixed Content Detector〉外掛本地化為台灣繁體中文版

對開發相關資訊感興趣?

任何人均可瀏覽程式碼、查看 SVN 存放庫,或透過 RSS 訂閱開發記錄

變更記錄

1.2.0

  • Add check for violation locations
  • Add sampling mode for examining non-logged in traffic
  • Add more content shown in the WP list table

1.1.0

  • Add check for HTTPS domain when logging violation
  • Add list, resolve, remove and unresolve WP CLI commands
  • Update CSP directives to be more specific

1.0.2

  • Remove false positives from the log

1.0.1

  • Limit logging to work only for admins

1.0.0

  • Initial release