=== Security Headers ===
Contributors: joshme21
Donate link: https://paypal.me/jose88882020
Tags: security headers, seo security headers
Requires at least: 6.0
Tested up to: 6.9.2
Stable tag: 1.5.0
Requires PHP: 7.4
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Security headers are directives used by web applications to configure browser-side security defenses.

== Description ==

Security Headers helps site owners manage modern browser security headers from inside WordPress.

Features include:

* Admin settings page under Security Headers
* HSTS controls with preload warning
* Referrer-Policy and X-Frame-Options settings
* Permissions-Policy custom value field
* Minimal enforced CSP with upgrade-insecure-requests, separate from advanced source restrictions
* Content-Security-Policy builder with Report-Only mode
* Diagnostics screen showing configured headers
* Test tool to fetch and inspect your live response headers
* Import, export, and reset settings tools
* Cleanup on uninstall

== Installation ==

1. Upload the plugin folder to `/wp-content/plugins/`
2. Activate the plugin in WordPress
3. Go to Security Headers in the admin menu
4. Save your preferred configuration
5. Purge page and hosting caches, then check the live headers on cached and uncached pages

== Frequently Asked Questions ==

= Is Content-Security-Policy enabled by default? =

New installs enable a minimal enforced `Content-Security-Policy: upgrade-insecure-requests` on HTTPS responses. It upgrades HTTP resource URLs to HTTPS without adding script or other source restrictions. Resources unavailable over HTTPS will fail to load. You can disable it using the HTTPS resource upgrades checkbox.

Existing installations keep their previous behaviour and must opt in to HTTPS resource upgrades after updating. Advanced CSP remains disabled by default because source restrictions need website-specific configuration.

= Should I use Report-Only mode first? =

Yes, for advanced CSP. Report-Only mode reports advanced policy issues without blocking resources. The separate HTTPS resource upgrades setting remains enforced even while advanced CSP is in Report-Only mode. When advanced CSP is enforced, the baseline directive is merged into that policy.

= Does this guarantee an A+ grade? =

No. A grade depends on the headers actually returned for each scanned URL and the scanner's criteria. The minimal upgrade policy does not restrict script sources or provide the XSS protection of a carefully configured CSP.

= Why are headers missing on cached pages? =

Page caches, hosting proxies, and CDNs can serve HTML without running WordPress. PHP headers cannot cover those responses. Apache rules can cover static cache files when Apache processes the plugin's generated .htaccess rules, but Nginx does not read .htaccess. Ask your host to apply security headers at the cache-serving layer and avoid duplicate headers. Purging caches alone may not solve the issue if the cache bypasses WordPress again.

Auto-detected advanced CSP requires WordPress to inspect rendered HTML. It cannot detect sources in a static cache response. Emergency CSP bypass also requires a WordPress-generated response and cannot bypass policies enforced by your server or CDN.

= Does HSTS work on HTTP sites? =

No. HSTS should only be enabled when your site is fully available over HTTPS.

== Why security headers important? ==

When auditing websites, security headers are frequently forgotten.

Although some may argue that website security is unrelated to SEO, it does become so when a site is compromised and search traffic completely disappears.

Everyone who publishes content online should pay special attention to security headers.

Getting hacked is not good. You lose traffic, customers and it’s a pain to resolve all the issues. 

But good thing you’re smart and have searched for this plugin :).

== Changelog ==

= 1.5.0 =
* Added an independent enforced upgrade-insecure-requests baseline for HTTPS responses.
* Enabled the baseline for new installs while preserving existing installations until they opt in.
* Kept advanced CSP configurable and Report-Only testing independent of the baseline.
* Merged the baseline into enforced advanced CSP without duplicating the directive.
* Prevented static Apache baseline rules from overwriting auto-detected enforced advanced CSP.
* Added HTTPS upgrade diagnostics, resource compatibility warnings, and cache guidance.

= 1.4.0 =
* Added best-effort CSP source detection from rendered HTML.
* Added a built-in CSP violation report collector and browser-only emergency bypass.

= 1.3.0 =
* Added diagnostics and live header testing tools in wp-admin.
* Added import, export, and reset tools for plugin settings.
* Added a configurable Content-Security-Policy builder with Report-Only support.
* Added uninstall cleanup for stored plugin options.

= 1.2.0 =
* Added a WordPress admin settings page under Settings > Security Headers.
* Added saved plugin options with sanitization and safer defaults.
* Connected PHP and Apache header output to the saved admin settings.

= 1.1.0 =
* Updated plugin metadata for modern WordPress compatibility.
* Removed deprecated legacy headers.
* Limited default headers to a conservative modern set to reduce breakage.
* Only sends HSTS on HTTPS requests.

= 1.0.0 =
* First release
