HTTP Headers

Àpèjúwe

HTTP Headers gives your control over the http headers returned by your blog or website.

Headers supported by HTTP Headers includes:

  • Access-Control-Allow-Origin
  • Access-Control-Allow-Credentials
  • Access-Control-Max-Age
  • Access-Control-Allow-Methods
  • Access-Control-Allow-Headers
  • Access-Control-Expose-Headers
  • Age
  • Content-Security-Policy
  • Content-Security-Policy-Report-Only
  • Cache-Control
  • Clear-Site-Data
  • Connection
  • Content-Encoding
  • Content-Type
  • Cross-Origin-Embedder-Policy
  • Cross-Origin-Opener-Policy
  • Cross-Origin-Resource-Policy
  • Expect-CT
  • Expires
  • Feature-Policy
  • NEL
  • Permissions-Policy
  • Pragma
  • P3P
  • Referrer-Policy
  • Report-To
  • Strict-Transport-Security
  • Timing-Allow-Origin
  • Vary
  • WWW-Authenticate
  • X-Content-Type-Options
  • X-DNS-Prefetch-Control
  • X-Download-Options
  • X-Frame-Options
  • X-Permitted-Cross-Domain-Policies
  • X-Powered-By
  • X-Robots-Tag
  • X-UA-Compatible
  • X-XSS-Protection

Àwọn àwòrán ìbòjú

Ìgbéwọlẹ̀

Upload the HTTP Headers plugin to your blog. Then activate it.

ThatÌtumọ̀ Yorùbá: ’s all.

FAQ

Why to use this plugin?

Nowadays security of your social data at the web is essential. This plugin helps you to improve your website overall security.

Who use these headers?

These HTTP headers are being used in production services by popular websites as Facebook, Google+, Twitter, LinkedIn, YouTube, Yahoo, Amazon, Instagram, Pinterest.

Àwọn àgbéyẹ̀wò

Ògún 30, 2025 2 àwọn ìdáhùn
Never use this plugin as the security settings make my main site and all sub-domain sites down and even after uninstallation / removal of everything and start to install a new WP, it doesnÌtumọ̀ Yorùbá: ’t work anymore
Ẹrẹ́nà 30, 2025
Went through a bunch of options of adding security headers to my sites and settled on this plugin. Would be 5 stars if two things get fixed/added. 1st is that it would be great to have a save button at the top also so you donÌtumọ̀ Yorùbá: ’t have to scroll so much to the bottom to save options (especially on CSP screen). And the 2nd would be that the boxes where we are able to input sites etc, sometimes you have to paste numerous websites in that field and it is ridiculously annoying to try to scroll through, see whats already there or copy and paste outside in notepad for example and then paste it back in. Would be great if that field could be expanded or just bigger.
Ọwẹ́wẹ̀ 23, 2024
When used with Elementor, you canÌtumọ̀ Yorùbá: ’t edit the pages. Had to uninstall, since I donÌtumọ̀ Yorùbá: ’t know what else it will break.
Èbìbí 11, 2024 2 àwọn ìdáhùn
I am finding this a very effective tool to help clients reach security compliance. There is one glitch I believe, however, is with the x-content-type-options. Once you enable this the only option is “nosniff”. And once enabled, there is no way to reset it. And unfortunately i believe this setting is creating errors on my site. I canÌtumọ̀ Yorùbá: ’t even seem to find the line for it in my .htaccess file. Any recommendations?
Igbe 30, 2024
I have felt this has been excellent since the first time I used it, and absolutely no issues with it for what it is, except that there are a couple of headers that either need to be ‘marked deprecated’ or just removed. My immediate spot of these are the, Features header, P3P header and the Expect-CT (which is still around, but Mozilla recommend not using). There may be others. There are a bunch of things that I might suggest as improvements, but this is to move the tool forward a bit. For instance: It would be great if it could display the highlighted state of the current Apache/Nginx code and the status of the security (as per securityheaders.com form) alongside/under it, so you could see the evolution of the security header set up arrangements as you add/remove them. Could be useful to have some in-built documentation on these things (particularly with the P3P header, those little summary items were impossible to figure out without going back and forth, but for other things like cache-control, or accept-expose-headers, some labelling could help). That said, for advanced users anyway, so perhaps less important. Further to that, it might be useful to have an indication of what OWASP, Scott Helme, and Mozilla recommend and/or warnings for ones that are problematic for security or high risk with labels on them. There are a few things that have odd formatting, so it is not obvious how to transpose the information for the reporting one over from how the header is laid out, since there are different ones for this. In this you have the report header that is normally used (as per report-uri site from Scott Helme) but it does not fit there. However, it has a group called ‘csp-element’ or something similar that might be clearer as to its use elsewhere). There is also the display of custom headers that are all grouped into one thing, and not spread out in a useful way if you want to review them. Odd grouping in a couple of places, so custom headers I might have given its own block for instance, and to have two items in one and even one in one grouping is a bit pointless. On another note, it is a shame that there is not a tool that is so effective that does this kind of thing for Wordpress and just outputs the BIND9 detail for DNS resource records. A combination of this and that, with the ability to adjust PHP and Apache settings would be the most amazing tool ever. For what this does, however, is sets the foundations for a great security setup.
Ka gbogbo àwọn àgbéyẹ̀wò 70

Àwọn Olùkópa & Olùgbéejáde

“HTTP Headers” jẹ́ ètò ìṣàmúlò orísun ṣíṣí sílẹ̀. Àwọn ènìyàn wọ̀nyí ti ṣe ìkópa sí plugin yìí.

Àwọn Olùkópa

A ti túmọ̀ “HTTP Headers” sí àwọn èdè agbègbè 5. Ọpẹ́lọpẹ́ fún àwọn atúmọ̀ èdè fún àwọn ìkópa wọn.

Túmọ̀ “HTTP Headers” sí èdè rẹ.

Ṣe o nífẹ̀ẹ́ sí ìdàgbàsókè?

Ṣàwárí koodu, ṣàyẹ̀wò ibi ìpamọ́ SVN, tàbí ṣe àgbékalẹ̀ sí àkọsílẹ̀ ìdàgbàsókè nípasẹ̀ RSS.

Àkọsílẹ̀ àwọn àyípadà

1.19.5

Release Date Ìtumọ̀ Yorùbá: – 27th April, 2026

  • Fixed: Global updated_option Nonce Redirect Bug

1.19.4

Release Date Ìtumọ̀ Yorùbá: – 25th April, 2026

  • Security vulnerabilities addressed
  • Coding best practices applied

1.19.3

Release Date Ìtumọ̀ Yorùbá: – 25th April, 2026

  • Security vulnerabilities addressed
  • Coding best practices applied

1.19.2

Release Date Ìtumọ̀ Yorùbá: – 22nd December, 2024

  • Added “script-src-elem” directive to “Content-Security-Policy” header
  • Added “script-src-attr” directive to “Content-Security-Policy” header
  • Added “style-src-elem” directive to “Content-Security-Policy” header
  • Added “style-src-attr” directive to “Content-Security-Policy” header

1.19.1

Release Date Ìtumọ̀ Yorùbá: – 2nd September, 2023

  • Added “clientHints” directive to “Clear-Site-Data” header
  • Added “credentialless” directive to “Cross-Origin-Embedder-Policy” header

1.19.0

Release Date Ìtumọ̀ Yorùbá: – 7th July, 2023

  • Fixed: SSRF vulnerability by an Admin user
  • Fixed: XSS vulnerability by an Admin user

1.18.11

Release Date Ìtumọ̀ Yorùbá: – 11th June, 2023

  • Fixed: Remote Code Execution by an Admin user

1.18.10

Release Date Ìtumọ̀ Yorùbá: – 28th May, 2023

  • Fixed: Remote Code Execution by an Admin user
  • Removed: Import/Export functions

1.18.9

Release Date Ìtumọ̀ Yorùbá: – 23rd April, 2023

  • Fixed: Remote Code Execution by an Admin user

1.18.8

Release Date Ìtumọ̀ Yorùbá: – 17th April, 2023

  • Fixed: SQL Injection by an Admin user
  • Fixed: Remote Code Execution by an Admin user
  • Few PHP 8.x compatible fixes

1.18.7

Release Date Ìtumọ̀ Yorùbá: – 24th January, 2023

  • Fix CSP default value

1.18.6

Release Date Ìtumọ̀ Yorùbá: – 22nd January, 2023

  • PHP 8 compatibility changes

1.18.5

Release Date Ìtumọ̀ Yorùbá: – 30th April, 2021

  • Configurable paths to files who store passwords for basic/digest auth
  • Fixed issue with plugin activation, due missing file

1.18.4

Release Date Ìtumọ̀ Yorùbá: – 30th April, 2021

  • Initial value of X-Robots-Tag fixed

1.18.3

Release Date Ìtumọ̀ Yorùbá: – 30th April, 2021

  • Added “X-Robots-Tag” header
  • Added “interest-cohort”, “layout-animations”, “legacy-image-formats”, “oversized-images”, and “wake-lock” directive to “Permissions-Policy” header
  • Added “cross-origin” value to “Cross-Origin-Resource-Policy” header
  • Added “navigate-to” and “prefetch-src” directives to “Content-Security-Policy” header

1.18.2

Release Date Ìtumọ̀ Yorùbá: – 24th April, 2021

  • Configurable paths to .htaccess and .user.ini files

1.18.1

Release Date Ìtumọ̀ Yorùbá: – 29th October, 2020

  • Added “allow-downloads” and “allow-top-navigation-by-user-activation” to “sandbox” directive, part of CSP

1.18.0

Release Date Ìtumọ̀ Yorùbá: – 20th September, 2020

  • Added “Permissions-Policy” header
  • Fixed “Cookie Security”

1.17.0

Release Date Ìtumọ̀ Yorùbá: – 26th July, 2020

  • Added “Cross-Origin-Embedder-Policy” header
  • Added “Cross-Origin-Opener-Policy” header

1.16.1

Release Date Ìtumọ̀ Yorùbá: – 23rd July, 2020

  • Fixed JS/CSS versioning

1.16.0

Release Date Ìtumọ̀ Yorùbá: – 23rd July, 2020

  • Added the “NEL” header
  • Fixed the “Report-To” header

1.15.2

Release Date Ìtumọ̀ Yorùbá: – 18th June, 2020

  • Fixed a PHP Notice at “Expires” page
  • Fixed comments in .user.ini file

1.15.1

Release Date Ìtumọ̀ Yorùbá: – 9th May, 2020

  • Fixed the “Access-Control-Allow-Origin” header

1.15.0

Release Date Ìtumọ̀ Yorùbá: – 26th January, 2020

  • Added the “Cross-Origin-Resource-Policy” header
  • Removed the “Public-Key-Pins” header

1.14.2

Release Date Ìtumọ̀ Yorùbá: – 25th November, 2019

  • CORS headers updated (added “Vary: Origin”)

1.14.1

Release Date Ìtumọ̀ Yorùbá: – 15th September, 2019

  • Simple filtering was replaced with Dynamic filtering

1.14.0

Release Date Ìtumọ̀ Yorùbá: – 1st September, 2019

  • Added the “Content-Type” header
  • Fixed the “Access-Control-Allow-Credentials” header
  • Improvement to “Access-Control-Allow-Headers” header
  • Improvement to “Access-Control-Allow-Methods” header
  • Improvement to “Access-Control-Expose-Headers” header
  • Improvement to “Cache-Control” header
  • Improvement to “Vary” header

1.13.4

Release Date Ìtumọ̀ Yorùbá: – 14th July, 2019

  • Added the “always” condition to Header (unset) directive
  • Fixed the “import” function
  • Fixed the “Access-Control-Allow-Origin” header

1.13.3

Release Date Ìtumọ̀ Yorùbá: – 16th June, 2019

  • Bugfix in “WWW-Authenticate” header
  • Added support of Apache 2.4

1.13.2

Release Date Ìtumọ̀ Yorùbá: – 13th June, 2019

  • Bugfix in “Content-Encoding” header
  • Bugfix in “Vary” header

1.13.1

Release Date Ìtumọ̀ Yorùbá: – 8th June, 2019

  • Added Brotli compression

1.13.0

Release Date Ìtumọ̀ Yorùbá: – 7th June, 2019

  • Added “SameSite” to Cookie Security
  • Fixed import/export function
  • Code refactoring

1.12.2

Release Date Ìtumọ̀ Yorùbá: – 5th April, 2019

  • UI improvement for Content-Security-Policy
  • Fix for Access-Control-Allow-Headers
  • Fix for Access-Control-Allow-Origin
  • Fix for Feature-Policy

1.12.1

Release Date Ìtumọ̀ Yorùbá: – 9th January, 2019

  • Remove direct calls to cURL

1.12.0

Release Date Ìtumọ̀ Yorùbá: – 5th January, 2019

  • Better handling of activate/deactivate functions

1.11.0

Release Date Ìtumọ̀ Yorùbá: – 9th December, 2018

  • Added support of “Clear-Site-Data” header

1.10.5

Release Date Ìtumọ̀ Yorùbá: – 6th November, 2018

  • Hotfix: parallel work with third-party plugins

1.10.4

Release Date Ìtumọ̀ Yorùbá: – 30th September, 2018

  • Support of following Server APIs: CGI, FastCGI, PHP-FPM
  • Error handling improvement

1.10.3

Release Date Ìtumọ̀ Yorùbá: – 8th August, 2018

  • HSTS improvement
  • CORS improvement

1.10.2

Release Date Ìtumọ̀ Yorùbá: – 31st July, 2018

  • Export feature bug-fixed

1.10.1

Release Date Ìtumọ̀ Yorùbá: – 18th July, 2018

  • Feature-Policy header update: new features added

1.10.0

Release Date Ìtumọ̀ Yorùbá: – 17th July, 2018

  • Added support of “Feature-Policy” header

1.9.5

Release Date Ìtumọ̀ Yorùbá: – 12th July, 2018

  • CORS bugfix

1.9.4

Release Date Ìtumọ̀ Yorùbá: – 13th January, 2018

  • In-plugin security improvement

1.9.3

Release Date Ìtumọ̀ Yorùbá: – 10th January, 2018

  • Bug fix

1.9.2

Release Date Ìtumọ̀ Yorùbá: – 4th January, 2018

  • Security improvements

1.9.1

Release Date Ìtumọ̀ Yorùbá: – 27th December, 2017

  • Updated translations

1.9.0

Release Date Ìtumọ̀ Yorùbá: – 23th December, 2017

  • Added support of “Report-To” header
  • Added support of translations
  • Added support of Import/Export
  • Updated “Content-Security-Policy” header (added directives: object-src, frame-src, worker-src, manifest-src, base-uri, report-to)
  • Updated “WWW-Authenticate” header (support multiple users)
  • Updated “Access-Control” headers (added list of origins)

1.8.0

Release Date Ìtumọ̀ Yorùbá: – 31st August, 2017

  • Added support of “Timing-Allow-Origin” header
  • Added support of “X-Download-Options” header
  • Added support of “X-DNS-Prefetch-Control” header
  • Added support of “X-Permitted-Cross-Domain-Policies” header
  • Added support of Custom headers

1.7.1

Release Date Ìtumọ̀ Yorùbá: – 18th August, 2017

  • PHP notice bugfixed

1.7.0

Release Date Ìtumọ̀ Yorùbá: – 15th August, 2017

  • Added support of “Content-Security-Policy-Report-Only” header
  • Added support of “Public-Key-Pins-Report-Only” header
  • Added “1; report=” directive to the “X-XSS-Protection” header
  • Added “Inspect headers” tool
  • UI bugfixes

1.6.0

Release Date Ìtumọ̀ Yorùbá: – 5th August, 2017

  • Added support of “Expect-CT” header

1.5.0

Release Date Ìtumọ̀ Yorùbá: – 30th July, 2017

  • Added support of “Age” header
  • Added support of “Cache-Control” header
  • Added support of “Connection” header
  • Added support of “Content-Encoding” header
  • Added support of “Expires” header
  • Added support of “Pragma” header
  • Added support of “Vary” header
  • Added support of “WWW-Authenticate” header
  • Added support of “X-Powered-By” header
  • Added support of “Secure” and “HttpOnly” cookies

1.4.0

Release Date Ìtumọ̀ Yorùbá: – 5th July, 2017

  • Added support of Apache (via htaccess) inclusion method

1.3.0

Release Date Ìtumọ̀ Yorùbá: – 3rd June, 2017

  • Added support of Content-Security-Policy header
  • Added dashboard

1.2.0

Release Date Ìtumọ̀ Yorùbá: – 28th April, 2017

  • Added support of Referrer-Policy header

1.1.2

Release Date Ìtumọ̀ Yorùbá: – 13th February, 2017

  • Added support of ‘preload’ directive to HSTS header

1.1.1

Release Date Ìtumọ̀ Yorùbá: – 8th November, 2016

  • Fixed typo in the X-Frame-Options header

1.1.0

Release Date Ìtumọ̀ Yorùbá: – 20th May, 2016

  • Added support of P3P header

1.0.0

Release Date Ìtumọ̀ Yorùbá: – 10th May, 2016

  • Initial version