| 1 |
=== HTTP Headers === |
| 2 |
Contributors: zinoui |
| 3 |
Donate link: https://zinoui.com/donation |
| 4 |
Tags: custom headers, http headers, headers, security, http header, header, cross domain, cors, xss, clickjacking, mitm, cross origin, cross site, privacy, p3p, hsts, referrer, csp, caching, compression, access control, authentication |
| 5 |
Requires at least: 3.2 |
| 6 |
Tested up to: 5.2.2 |
| 7 |
Stable tag: 1.13.4 |
| 8 |
License: GPLv2 or later |
| 9 |
|
| 10 |
HTTP Headers adds CORS & security HTTP headers to your website. |
| 11 |
|
| 12 |
== Description == |
| 13 |
|
| 14 |
HTTP Headers gives your control over the http headers returned by your blog or website. |
| 15 |
|
| 16 |
Headers supported by HTTP Headers includes: |
| 17 |
|
| 18 |
* Access-Control-Allow-Origin |
| 19 |
* Access-Control-Allow-Credentials |
| 20 |
* Access-Control-Max-Age |
| 21 |
* Access-Control-Allow-Methods |
| 22 |
* Access-Control-Allow-Headers |
| 23 |
* Access-Control-Expose-Headers |
| 24 |
* Age |
| 25 |
* Content-Security-Policy |
| 26 |
* Content-Security-Policy-Report-Only |
| 27 |
* Cache-Control |
| 28 |
* Clear-Site-Data |
| 29 |
* Connection |
| 30 |
* Content-Encoding |
| 31 |
* Expect-CT |
| 32 |
* Expires |
| 33 |
* Feature-Policy |
| 34 |
* Pragma |
| 35 |
* Public-Key-Pins |
| 36 |
* Public-Key-Pins-Report-Only |
| 37 |
* P3P |
| 38 |
* Referrer-Policy |
| 39 |
* Report-To |
| 40 |
* Strict-Transport-Security |
| 41 |
* Timing-Allow-Origin |
| 42 |
* Vary |
| 43 |
* WWW-Authenticate |
| 44 |
* X-Content-Type-Options |
| 45 |
* X-DNS-Prefetch-Control |
| 46 |
* X-Download-Options |
| 47 |
* X-Frame-Options |
| 48 |
* X-Permitted-Cross-Domain-Policies |
| 49 |
* X-Powered-By |
| 50 |
* X-UA-Compatible |
| 51 |
* X-XSS-Protection |
| 52 |
|
| 53 |
The [getting started tutorial](https://zinoui.com/blog/http-headers-for-wordpress) describes a typical configuration of this plugin. |
| 54 |
|
| 55 |
== Installation == |
| 56 |
|
| 57 |
Upload the HTTP Headers plugin to your blog. Then activate it. |
| 58 |
|
| 59 |
That's all. |
| 60 |
|
| 61 |
== Frequently Asked Questions == |
| 62 |
|
| 63 |
= Why to use this plugin? = |
| 64 |
|
| 65 |
Nowadays security of your social data at the web is essential. This plugin helps you to improve your website overall security. |
| 66 |
|
| 67 |
= Who use these headers? = |
| 68 |
|
| 69 |
These HTTP headers are being used in production services by popular websites as Facebook, Google+, Twitter, LinkedIn, YouTube, Yahoo, Amazon, Instagram, Pinterest. |
| 70 |
|
| 71 |
== Screenshots == |
| 72 |
|
| 73 |
1. This screenshot shows up the dashboard with categories of the supported headers. |
| 74 |
2. This screenshot shows up the headers of a chosen category and their current values. |
| 75 |
3. This screenshot shows up the settings page where you can adjust the security headers. |
| 76 |
4. This screenshot shows up the response headers returned by the web server. |
| 77 |
|
| 78 |
== Upgrade Notice == |
| 79 |
|
| 80 |
Updates are on they way, so stay tuned at [@DimitarIvanov](https://twitter.com/DimitarIvanov) |
| 81 |
|
| 82 |
== Changelog == |
| 83 |
|
| 84 |
= 1.13.4 = |
| 85 |
*Release Date - 14th July, 2019* |
| 86 |
|
| 87 |
* Added the "always" condition to Header (unset) directive |
| 88 |
* Fixed the "import" function |
| 89 |
* Fixed the "Access-Control-Allow-Origin" header |
| 90 |
|
| 91 |
= 1.13.3 = |
| 92 |
*Release Date - 16th June, 2019* |
| 93 |
|
| 94 |
* Bugfix in "WWW-Authenticate" header |
| 95 |
* Added support of Apache 2.4 |
| 96 |
|
| 97 |
= 1.13.2 = |
| 98 |
*Release Date - 13th June, 2019* |
| 99 |
|
| 100 |
* Bugfix in "Content-Encoding" header |
| 101 |
* Bugfix in "Vary" header |
| 102 |
|
| 103 |
= 1.13.1 = |
| 104 |
*Release Date - 8th June, 2019* |
| 105 |
|
| 106 |
* Added Brotli compression |
| 107 |
|
| 108 |
= 1.13.0 = |
| 109 |
*Release Date - 7th June, 2019* |
| 110 |
|
| 111 |
* Added "SameSite" to Cookie Security |
| 112 |
* Fixed import/export function |
| 113 |
* Code refactoring |
| 114 |
|
| 115 |
= 1.12.2 = |
| 116 |
*Release Date - 5th April, 2019* |
| 117 |
|
| 118 |
* UI improvement for Content-Security-Policy |
| 119 |
* Fix for Access-Control-Allow-Headers |
| 120 |
* Fix for Access-Control-Allow-Origin |
| 121 |
* Fix for Feature-Policy |
| 122 |
|
| 123 |
= 1.12.1 = |
| 124 |
*Release Date - 9th January, 2019* |
| 125 |
|
| 126 |
* Remove direct calls to cURL |
| 127 |
|
| 128 |
= 1.12.0 = |
| 129 |
*Release Date - 5th January, 2019* |
| 130 |
|
| 131 |
* Better handling of activate/deactivate functions |
| 132 |
|
| 133 |
= 1.11.0 = |
| 134 |
*Release Date - 9th December, 2018* |
| 135 |
|
| 136 |
* Added support of "Clear-Site-Data" header |
| 137 |
|
| 138 |
= 1.10.5 = |
| 139 |
*Release Date - 6th November, 2018* |
| 140 |
|
| 141 |
* Hotfix: parallel work with third-party plugins |
| 142 |
|
| 143 |
= 1.10.4 = |
| 144 |
*Release Date - 30th September, 2018* |
| 145 |
|
| 146 |
* Support of following Server APIs: CGI, FastCGI, PHP-FPM |
| 147 |
* Error handling improvement |
| 148 |
|
| 149 |
= 1.10.3 = |
| 150 |
*Release Date - 8th August, 2018* |
| 151 |
|
| 152 |
* HSTS improvement |
| 153 |
* CORS improvement |
| 154 |
|
| 155 |
= 1.10.2 = |
| 156 |
*Release Date - 31st July, 2018* |
| 157 |
|
| 158 |
* Export feature bug-fixed |
| 159 |
|
| 160 |
= 1.10.1 = |
| 161 |
*Release Date - 18th July, 2018* |
| 162 |
|
| 163 |
* Feature-Policy header update: new features added |
| 164 |
|
| 165 |
= 1.10.0 = |
| 166 |
*Release Date - 17th July, 2018* |
| 167 |
|
| 168 |
* Added support of "Feature-Policy" header |
| 169 |
|
| 170 |
= 1.9.5 = |
| 171 |
*Release Date - 12th July, 2018* |
| 172 |
|
| 173 |
* CORS bugfix |
| 174 |
|
| 175 |
= 1.9.4 = |
| 176 |
*Release Date - 13th January, 2018* |
| 177 |
|
| 178 |
* In-plugin security improvement |
| 179 |
|
| 180 |
= 1.9.3 = |
| 181 |
*Release Date - 10th January, 2018* |
| 182 |
|
| 183 |
* Bug fix |
| 184 |
|
| 185 |
= 1.9.2 = |
| 186 |
*Release Date - 4th January, 2018* |
| 187 |
|
| 188 |
* Security improvements |
| 189 |
|
| 190 |
= 1.9.1 = |
| 191 |
*Release Date - 27th December, 2017* |
| 192 |
|
| 193 |
* Updated translations |
| 194 |
|
| 195 |
= 1.9.0 = |
| 196 |
*Release Date - 23th December, 2017* |
| 197 |
|
| 198 |
* Added support of "Report-To" header |
| 199 |
* Added support of translations |
| 200 |
* Added support of Import/Export |
| 201 |
* Updated "Content-Security-Policy" header (added directives: object-src, frame-src, worker-src, manifest-src, base-uri, report-to) |
| 202 |
* Updated "WWW-Authenticate" header (support multiple users) |
| 203 |
* Updated "Access-Control" headers (added list of origins) |
| 204 |
|
| 205 |
= 1.8.0 = |
| 206 |
*Release Date - 31st August, 2017* |
| 207 |
|
| 208 |
* Added support of "Timing-Allow-Origin" header |
| 209 |
* Added support of "X-Download-Options" header |
| 210 |
* Added support of "X-DNS-Prefetch-Control" header |
| 211 |
* Added support of "X-Permitted-Cross-Domain-Policies" header |
| 212 |
* Added support of Custom headers |
| 213 |
|
| 214 |
= 1.7.1 = |
| 215 |
*Release Date - 18th August, 2017* |
| 216 |
|
| 217 |
* PHP notice bugfixed |
| 218 |
|
| 219 |
= 1.7.0 = |
| 220 |
*Release Date - 15th August, 2017* |
| 221 |
|
| 222 |
* Added support of "Content-Security-Policy-Report-Only" header |
| 223 |
* Added support of "Public-Key-Pins-Report-Only" header |
| 224 |
* Added "1; report=<reporting-URI>" directive to the "X-XSS-Protection" header |
| 225 |
* Added "Inspect headers" tool |
| 226 |
* UI bugfixes |
| 227 |
|
| 228 |
= 1.6.0 = |
| 229 |
*Release Date - 5th August, 2017* |
| 230 |
|
| 231 |
* Added support of "Expect-CT" header |
| 232 |
|
| 233 |
= 1.5.0 = |
| 234 |
*Release Date - 30th July, 2017* |
| 235 |
|
| 236 |
* Added support of "Age" header |
| 237 |
* Added support of "Cache-Control" header |
| 238 |
* Added support of "Connection" header |
| 239 |
* Added support of "Content-Encoding" header |
| 240 |
* Added support of "Expires" header |
| 241 |
* Added support of "Pragma" header |
| 242 |
* Added support of "Vary" header |
| 243 |
* Added support of "WWW-Authenticate" header |
| 244 |
* Added support of "X-Powered-By" header |
| 245 |
* Added support of "Secure" and "HttpOnly" cookies |
| 246 |
|
| 247 |
= 1.4.0 = |
| 248 |
*Release Date - 5th July, 2017* |
| 249 |
|
| 250 |
* Added support of Apache (via htaccess) inclusion method |
| 251 |
|
| 252 |
= 1.3.0 = |
| 253 |
*Release Date - 3rd June, 2017* |
| 254 |
|
| 255 |
* Added support of Content-Security-Policy header |
| 256 |
* Added dashboard |
| 257 |
|
| 258 |
= 1.2.0 = |
| 259 |
*Release Date - 28th April, 2017* |
| 260 |
|
| 261 |
* Added support of Referrer-Policy header |
| 262 |
|
| 263 |
= 1.1.2 = |
| 264 |
*Release Date - 13th February, 2017* |
| 265 |
|
| 266 |
* Added support of 'preload' directive to HSTS header |
| 267 |
|
| 268 |
= 1.1.1 = |
| 269 |
*Release Date - 8th November, 2016* |
| 270 |
|
| 271 |
* Fixed typo in the X-Frame-Options header |
| 272 |
|
| 273 |
= 1.1.0 = |
| 274 |
*Release Date - 20th May, 2016* |
| 275 |
|
| 276 |
* Added support of P3P header |
| 277 |
|
| 278 |
= 1.0.0 = |
| 279 |
*Release Date - 10th May, 2016* |
| 280 |
|
| 281 |
* Initial version |
| 282 |
|