plugin-icon

Fix It Easy Security Headers

Configure core HTTP security headers for your WordPress site in a few clicks.
버전
1.1
최근 업데이트일
Aug 24, 2025
Fix It Easy Security Headers

WP Fix It Easy Security Headers adds a simple page under Tools Security Headers where you can toggle common HTTP security headers:

  • Strict-Transport-Security (HSTS)
  • Content-Security-Policy (CSP)
  • X-Frame-Options
  • X-Content-Type-Options
  • Referrer-Policy
  • Permissions-Policy

On activation, all headers are enabled by default and you’re redirected to the settings screen.

For convenience, the page and the Plugins screen include a “Check Headers” button that opens SecurityHeaders.com with your site’s URL prefilled (built dynamically from home_url()).

Notes on CSP

This plugin ships with a permissive default CSP intended to “work everywhere” out of the box (allows most external sources and inline code). For stronger protection, you should harden the directives for your specific site.

Key Features

  • One-click toggles for popular headers
  • Dynamic “Check Headers” scan link
  • Uses the WordPress Settings API (nonce + capability checks)
  • Output escaping and sanitization following PHPCS
무료Business 요금제에서
설치하면 WordPress.com 서비스 약관서드파티 플러그인 약관에 동의하게 됩니다.
테스트된 버전
WordPress 6.8.3
이 플러그인은 다운로드할 수 있으며 에서 사용할 수 있습니다.