| 开发者 | rimbeplus |
|---|---|
| 更新时间 | 2026年8月19日 18:00 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
/wp-content/plugins/beplus-security-headers-script-auditor directory, or install the plugin through the WordPress plugins screen directly.It can, especially Content-Security-Policy. Start with the scanner recommendations, use "Report-only mode" for CSP first to observe without blocking anything, and only switch to enforcing mode once you've confirmed the policy covers everything your site actually loads.
No. It performs normal HTTP requests from your own server to pages on your own site, using the built-in WordPress HTTP API. Nothing is sent to any third party.
No. Even the whole-site option only scans your homepage plus your most recently published posts/pages (capped at 200) and is meant as a starting point for building a Content-Security-Policy, not a substitute for a complete security review of your site.