Skip to content

Instantly share code, notes, and snippets.

Last active Feb 5, 2021
What would you like to do?
WordPress: Security Headers
# Add the following security headers in the root .htaccess file of WordPress #
# Get A+ Security Headers Score under #
<IfModule mod_headers.c>
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains"
Header set Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://* https://* https://* https://*; img-src 'self' data: https://* https://* https://*; style-src 'self' 'unsafe-inline' https://* https://*; font-src 'self' data:; frame-src 'self' https://* https://* https://*; object-src 'none';"
Header set X-Content-Type-Options nosniff
Header always set X-XSS-Protection "1; mode=block"
Header always set Expect-CT "max-age=604800, enforce"
Header set Referrer-Policy "strict-origin"
Header always append X-Frame-Options SAMEORIGIN
Header always set Permissions-Policy "accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=();"
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment