PluginProbe
HTTP Headers / 1.13.1
HTTP Headers v1.13.1
1.19.5 trunk 1.0.0 1.1.0 1.1.1 1.1.2 1.10.0 1.10.1 1.10.2 1.10.3 1.10.4 1.10.5 1.11.0 1.12.0 1.12.1 1.12.2 1.13.0 1.13.1 1.13.2 1.13.3 1.13.4 1.14.0 1.14.1 1.14.2 1.15.0 All 60 releases
http-headers / README.txt

README.txt in HTTP Headers 1.13.1, at README.txt

263 lines 6.4 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 === HTTP Headers ===
2 Contributors: zinoui
3 Donate link: https://zinoui.com/donation
4 Tags: custom headers, http headers, headers, security, http header, header, cross domain, cors, xss, clickjacking, mitm, cross origin, cross site, privacy, p3p, hsts, referrer, csp, caching, compression, access control, authentication
5 Requires at least: 3.2
6 Tested up to: 5.2.1
7 Stable tag: 1.13.1
8 License: GPLv2 or later
9
10 HTTP Headers adds CORS & security HTTP headers to your website.
11
12 == Description ==
13
14 HTTP Headers gives your control over the http headers returned by your blog or website.
15
16 Headers supported by HTTP Headers includes:
17
18 * Access-Control-Allow-Origin
19 * Access-Control-Allow-Credentials
20 * Access-Control-Max-Age
21 * Access-Control-Allow-Methods
22 * Access-Control-Allow-Headers
23 * Access-Control-Expose-Headers
24 * Age
25 * Content-Security-Policy
26 * Content-Security-Policy-Report-Only
27 * Cache-Control
28 * Clear-Site-Data
29 * Connection
30 * Content-Encoding
31 * Expect-CT
32 * Expires
33 * Feature-Policy
34 * Pragma
35 * Public-Key-Pins
36 * Public-Key-Pins-Report-Only
37 * P3P
38 * Referrer-Policy
39 * Report-To
40 * Strict-Transport-Security
41 * Timing-Allow-Origin
42 * Vary
43 * WWW-Authenticate
44 * X-Content-Type-Options
45 * X-DNS-Prefetch-Control
46 * X-Download-Options
47 * X-Frame-Options
48 * X-Permitted-Cross-Domain-Policies
49 * X-Powered-By
50 * X-UA-Compatible
51 * X-XSS-Protection
52
53 The [getting started tutorial](https://zinoui.com/blog/http-headers-for-wordpress) describes a typical configuration of this plugin.
54
55 == Installation ==
56
57 Upload the HTTP Headers plugin to your blog. Then activate it.
58
59 That's all.
60
61 == Frequently Asked Questions ==
62
63 = Why to use this plugin? =
64
65 Nowadays security of your social data at the web is essential. This plugin helps you to improve your website overall security.
66
67 = Who use these headers? =
68
69 These HTTP headers are being used in production services by popular websites as Facebook, Google+, Twitter, LinkedIn, YouTube, Yahoo, Amazon, Instagram, Pinterest.
70
71 == Screenshots ==
72
73 1. This screenshot shows up the dashboard with categories of the supported headers.
74 2. This screenshot shows up the headers of a chosen category and their current values.
75 3. This screenshot shows up the settings page where you can adjust the security headers.
76 4. This screenshot shows up the response headers returned by the web server.
77
78 == Upgrade Notice ==
79
80 Updates are on they way, so stay tuned at [@DimitarIvanov](https://twitter.com/DimitarIvanov)
81
82 == Changelog ==
83
84 = 1.13.1 =
85 *Release Date - 8th June, 2019*
86
87 * Added Brotli compression
88
89 = 1.13.0 =
90 *Release Date - 7th June, 2019*
91
92 * Added "SameSite" to Cookie Security
93 * Fixed import/export function
94 * Code refactoring
95
96 = 1.12.2 =
97 *Release Date - 5th April, 2019*
98
99 * UI improvement for Content-Security-Policy
100 * Fix for Access-Control-Allow-Headers
101 * Fix for Access-Control-Allow-Origin
102 * Fix for Feature-Policy
103
104 = 1.12.1 =
105 *Release Date - 9th January, 2019*
106
107 * Remove direct calls to cURL
108
109 = 1.12.0 =
110 *Release Date - 5th January, 2019*
111
112 * Better handling of activate/deactivate functions
113
114 = 1.11.0 =
115 *Release Date - 9th December, 2018*
116
117 * Added support of "Clear-Site-Data" header
118
119 = 1.10.5 =
120 *Release Date - 6th November, 2018*
121
122 * Hotfix: parallel work with third-party plugins
123
124 = 1.10.4 =
125 *Release Date - 30th September, 2018*
126
127 * Support of following Server APIs: CGI, FastCGI, PHP-FPM
128 * Error handling improvement
129
130 = 1.10.3 =
131 *Release Date - 8th August, 2018*
132
133 * HSTS improvement
134 * CORS improvement
135
136 = 1.10.2 =
137 *Release Date - 31st July, 2018*
138
139 * Export feature bug-fixed
140
141 = 1.10.1 =
142 *Release Date - 18th July, 2018*
143
144 * Feature-Policy header update: new features added
145
146 = 1.10.0 =
147 *Release Date - 17th July, 2018*
148
149 * Added support of "Feature-Policy" header
150
151 = 1.9.5 =
152 *Release Date - 12th July, 2018*
153
154 * CORS bugfix
155
156 = 1.9.4 =
157 *Release Date - 13th January, 2018*
158
159 * In-plugin security improvement
160
161 = 1.9.3 =
162 *Release Date - 10th January, 2018*
163
164 * Bug fix
165
166 = 1.9.2 =
167 *Release Date - 4th January, 2018*
168
169 * Security improvements
170
171 = 1.9.1 =
172 *Release Date - 27th December, 2017*
173
174 * Updated translations
175
176 = 1.9.0 =
177 *Release Date - 23th December, 2017*
178
179 * Added support of "Report-To" header
180 * Added support of translations
181 * Added support of Import/Export
182 * Updated "Content-Security-Policy" header (added directives: object-src, frame-src, worker-src, manifest-src, base-uri, report-to)
183 * Updated "WWW-Authenticate" header (support multiple users)
184 * Updated "Access-Control" headers (added list of origins)
185
186 = 1.8.0 =
187 *Release Date - 31st August, 2017*
188
189 * Added support of "Timing-Allow-Origin" header
190 * Added support of "X-Download-Options" header
191 * Added support of "X-DNS-Prefetch-Control" header
192 * Added support of "X-Permitted-Cross-Domain-Policies" header
193 * Added support of Custom headers
194
195 = 1.7.1 =
196 *Release Date - 18th August, 2017*
197
198 * PHP notice bugfixed
199
200 = 1.7.0 =
201 *Release Date - 15th August, 2017*
202
203 * Added support of "Content-Security-Policy-Report-Only" header
204 * Added support of "Public-Key-Pins-Report-Only" header
205 * Added "1; report=<reporting-URI>" directive to the "X-XSS-Protection" header
206 * Added "Inspect headers" tool
207 * UI bugfixes
208
209 = 1.6.0 =
210 *Release Date - 5th August, 2017*
211
212 * Added support of "Expect-CT" header
213
214 = 1.5.0 =
215 *Release Date - 30th July, 2017*
216
217 * Added support of "Age" header
218 * Added support of "Cache-Control" header
219 * Added support of "Connection" header
220 * Added support of "Content-Encoding" header
221 * Added support of "Expires" header
222 * Added support of "Pragma" header
223 * Added support of "Vary" header
224 * Added support of "WWW-Authenticate" header
225 * Added support of "X-Powered-By" header
226 * Added support of "Secure" and "HttpOnly" cookies
227
228 = 1.4.0 =
229 *Release Date - 5th July, 2017*
230
231 * Added support of Apache (via htaccess) inclusion method
232
233 = 1.3.0 =
234 *Release Date - 3rd June, 2017*
235
236 * Added support of Content-Security-Policy header
237 * Added dashboard
238
239 = 1.2.0 =
240 *Release Date - 28th April, 2017*
241
242 * Added support of Referrer-Policy header
243
244 = 1.1.2 =
245 *Release Date - 13th February, 2017*
246
247 * Added support of 'preload' directive to HSTS header
248
249 = 1.1.1 =
250 *Release Date - 8th November, 2016*
251
252 * Fixed typo in the X-Frame-Options header
253
254 = 1.1.0 =
255 *Release Date - 20th May, 2016*
256
257 * Added support of P3P header
258
259 = 1.0.0 =
260 *Release Date - 10th May, 2016*
261
262 * Initial version
263