
內容簡介
Beplus Security Headers & Script Auditor 是一款專為 WordPress 網站設計的安全外掛,提供安全標頭管理、外部資源掃描及自訂建議功能,幫助網站擁有者強化安全性並簡化設定過程。
【主要功能】
• 安全標頭切換功能
• 網站資源掃描器
• 自訂建議與即時預覽
• 自訂回應標頭的重複表格
• 無需外部服務呼叫
外掛標籤
開發者團隊
② 後台搜尋「Beplus Security Headers & Script Auditor」→ 直接安裝(推薦)
原文外掛簡介
Beplus Security Headers & Script Auditor gives WordPress site owners three things in one screen:
Security header toggles — enable X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Strict-Transport-Security, Permissions-Policy, Content-Security-Policy (with an optional report-only mode), and the legacy X-XSS-Protection header, each with sensible defaults.
A scanner — fetches your homepage, or optionally your whole site (up to 200 of your most recently published posts/pages), and lists every external script, stylesheet, image, iframe, and form target it finds, plus a count of inline scripts/styles.
Recommendations you control — every finding is listed as a checkbox row; uncheck anything you don’t want, and the Content-Security-Policy preview updates live. Apply the checked rows to the CSP field with one click, review it, then press Save. Nothing is ever sent automatically.
There’s also a repeatable table for adding any other custom response header your site needs.
Why use this plugin
No external service calls, tracking, or phone-home behaviour — the scan only requests pages on your own site.
Every setting is sanitized on save, and header values are stripped of line breaks to prevent HTTP header injection.
Sensible, conservative defaults: only X-Frame-Options, X-Content-Type-Options, and Referrer-Policy are enabled out of the box. HSTS, Permissions-Policy, CSP, and X-XSS-Protection are opt-in since they can affect how your site behaves and should be reviewed first.
