=== 360 Orbit Header Security ===
Contributors: joergliwa
Tags: security, http headers, hsts, security headers, clickjacking
Requires at least: 6.4
Tested up to: 7.1
Requires PHP: 8.1
Stable tag: 1.0.23
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Sets modern HTTP security headers (HSTS, X-Frame-Options, Referrer-Policy, Permissions-Policy and more) with a one-click quickstart and clear options.

== Description ==

Header Security brings your website up to date with current HTTP security headers:

* Strict-Transport-Security (HSTS)
* X-Frame-Options and CSP frame-ancestors (clickjacking protection, even without a full CSP)
* X-Content-Type-Options
* Referrer-Policy
* Permissions-Policy
* Cross-Origin-Opener-Policy / Cross-Origin-Resource-Policy
* Cookie hardening: adds missing Secure and SameSite attributes to all cookies the website sends

Each header can be switched on and off individually, and its values are fully configurable. A quickstart button enables the recommended settings with a single click.

= Free vs. Pro =

The free version fully covers all of the basic headers listed above for the frontend.

**Header Security Pro** adds:

* Content Security Policy (CSP), including a report-only mode for a low-risk start.
* Learning mode: collects everything the CSP would block for a configurable period and only switches to enforcing once no finding is left unreviewed.
* A scanner that automatically detects the external services your site needs (scripts, styles, images, fonts, iframes) and presents them for approval, including bulk approve/block.
* Separate header configuration for the backend (wp-admin); WordPress's own services are allowed automatically.
* Automatic update notifications directly in the WordPress backend.

== Installation ==

1. Install the plugin under *Plugins > Add New* (search for "360 Orbit Header Security"), or upload the ZIP under *Plugins > Add New > Upload Plugin*.
2. Activate the plugin.
3. In the **Header Security** menu, click "Run quickstart" or configure the headers individually.

== Frequently Asked Questions ==

= Can I accidentally break my website with this? =

The quickstart defaults are deliberately cautious (for example, X-Frame-Options: SAMEORIGIN instead of DENY, so the WordPress Customizer keeps working). The Content Security Policy (Pro) starts in report-only mode by default, which does not block anything and only reports.

= Do I have to use a Content Security Policy? =

No. CSP is optional and only available in the Pro version anyway. The basic headers of the free version work independently of it.

= Who is liable in case of damage? =

This plugin is provided without any warranty ("as is"). The developer accepts no liability for data loss or damage resulting from the use of the plugin (for example, from an overly restrictive header configuration). Before using it, you are strongly advised to create a full backup and to test changes in report-only mode first.

= Does the plugin change files or contact other servers? =

By default it only sends headers from PHP. Optionally you can switch on the ".htaccess mirror": the plugin then writes its own marked block into your `.htaccess` (so the headers also reach cached pages) and tests your homepage with a request to your own site, rolling back automatically if the site stops responding. While that block exists, the plugin also keeps a small guard file in `wp-content/mu-plugins/` that removes the block should the plugin folder ever be deleted without deactivating it; deactivating or deleting the plugin removes both. No data is sent to any other server.

= Does it work on multisite? =

The headers work on every site. Because the `.htaccess` file is shared by the whole network, only a super admin can use the ".htaccess mirror" on multisite.

= Which languages is the backend available in? =

The backend follows the language set in WordPress. Translations are provided through translate.wordpress.org and you are welcome to contribute one for your language.

== Screenshots ==

1. Status overview (free version) with the quickstart button. The Content Security Policy and the backend configuration are Pro features.

== Changelog ==

= 1.0.23 =
* Changed: the introduction on the settings page and in the help tab now describes only what the free version does (the frontend headers); the text about the Content Security Policy and the backend belongs to Pro.

= 1.0.22 =
* Changed: corrected plugin logo -- lettering and symbol are now centered, the orbit is a closed ring.

= 1.0.21 =
* First release on WordPress.org, including the results of an internal security review.
* Fix: the optional HTTPS redirect no longer drops encoded characters (umlauts) from the address, no longer doubles the path on installations in a subdirectory and no longer redirects form submissions.
* Fix: the .htaccess mirror and its guard file are now only created while the mirror is switched on, and on multisite only a super admin can use it. The quickstart updates the mirror as well.
* Fix: the one-time data migration from older versions now only touches this plugin's own, exactly named data and no longer clears the whole object cache.
* Fix: values written to the .htaccess block are escaped completely; the homepage test honors the https_local_ssl_verify filter.
* Fix: a Content-Security-Policy header set by another plugin is no longer overwritten by the frame-ancestors header.
* Fix: uninstalling removes the data of every site on multisite and the guard file.
* Changed: the German translation is now also used for Austrian, Swiss and formal German.

== Upgrade Notice ==



