Skip to content

Instantly share code, notes, and snippets.

@z2z
Created May 3, 2019 08:10
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save z2z/fdf5f07d19bb16a895a876ff2abd2768 to your computer and use it in GitHub Desktop.
Save z2z/fdf5f07d19bb16a895a876ff2abd2768 to your computer and use it in GitHub Desktop.
Apache WP Security Headers
# Extra Security Headers
<IfModule mod_headers.c>
Header unset Server
Header set X-XSS-Protection "1; mode=block"
# Header always append X-Frame-Options SAMEORIGIN
Header set Strict-Transport-Security "max-age=10886400; includeSubDomains; preload"
Header set X-Content-Type-Options nosniff
Header set Referrer-Policy: no-referrer-when-downgrade
Header always set Feature-Policy "microphone 'none'; payment 'none'; sync-xhr 'self' https://yourdomainname.com"
</IfModule>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment