| 开发者 | joergliwa |
|---|---|
| 更新时间 | 2026年10月7日 17:18 |
| PHP版本: | 8.1 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
The quickstart defaults are deliberately cautious (for example, X-Frame-Options: SAMEORIGIN instead of DENY, so the WordPress Customizer keeps working). The Content Security Policy (Pro) starts in report-only mode by default, which does not block anything and only reports.
No. CSP is optional and only available in the Pro version anyway. The basic headers of the free version work independently of it.
This plugin is provided without any warranty ("as is"). The developer accepts no liability for data loss or damage resulting from the use of the plugin (for example, from an overly restrictive header configuration). Before using it, you are strongly advised to create a full backup and to test changes in report-only mode first.
By default it only sends headers from PHP. Optionally you can switch on the ".htaccess mirror": the plugin then writes its own marked block into your .htaccess (so the headers also reach cached pages) and tests your homepage with a request to your own site, rolling back automatically if the site stops responding. While that block exists, the plugin also keeps a small guard file in wp-content/mu-plugins/ that removes the block should the plugin folder ever be deleted without deactivating it; deactivating or deleting the plugin removes both. No data is sent to any other server.
The headers work on every site. Because the .htaccess file is shared by the whole network, only a super admin can use the ".htaccess mirror" on multisite.
The backend follows the language set in WordPress. Translations are provided through translate.wordpress.org and you are welcome to contribute one for your language.