This plugin addresses the need for a simple way to add HTTP headers to outbound HTTP responses in your site.
These headers can include custom ones specific to your application, or can be security related. Some you may wish to specify to protect your site may include:
- Public-Key-Pins
- Strict-Transport-Security
- X-Frame-Options
- X-XSS-Protection
- X-Content-Type-Options
- Content-Security-Policy
- Content-Security-Policy-Report-Only
This section describes how to install the plugin and get it working.
- Upload the plugin files to the
/wp-content/plugins/headit
directory, or install the plugin through the WordPress plugins screen directly
- Activate the plugin through the
Plugins
screen in WordPress
- Use the Settings->Headit screen to configure the plugin