
內容簡介
BoundaryGuard Headers 是一款強化 WordPress 網站安全性的外掛,透過現代 HTTP 安全標頭來防範 XSS、點擊劫持、混合內容及跨來源攻擊,提升網站的整體安全性。
【主要功能】
• 增加 X-Frame-Options 和 Referrer-Policy 以減少攻擊面
• 強制 HTTPS 連線以防止協議降級攻擊
• 啟用 Cross-Origin-Opener-Policy 以改善跨來源隔離
• 提供 CSP 建構器以防範 XSS 攻擊
• 實時檢查網站的 HTTP 回應標頭
• 支援配置匯入/匯出功能以便於管理
外掛標籤
開發者團隊
原文外掛簡介
BoundaryGuard Headers enforces modern HTTP security headers to harden your WordPress site against XSS, clickjacking, mixed content, and cross-origin attacks.
Key Features:
Essential Protection: Adds X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy to reduce attack surface and prevent clickjacking.
HSTS (Strict Transport Security): Forces HTTPS connections to help prevent protocol downgrade and man-in-the-middle attacks.
Advanced Isolation (COOP/COEP): Enables Cross-Origin-Opener-Policy and Cross-Origin-Embedder-Policy to improve cross-origin isolation and mitigate certain side-channel attacks.
Content Security Policy (CSP): One of the strongest defenses against XSS. Includes a dashboard-based CSP builder with one-click presets to whitelist trusted sources for scripts, iframes, API endpoints, and images.
CSP Report-Only Mode & Nonce Mode: Test your policy safely without blocking content, then move to per-request script nonces for the strongest possible policy.
Security Score: A 0-100 score and A+-to-F grade computed from your settings, with an itemized checklist showing exactly what’s missing.
Live Header Scan: Checks your site’s actual live HTTP response headers so protection already provided by your host, theme, another plugin, or a CDN is correctly detected and credited.
CSP Violation Log: A visual dashboard (14-day trend, top blocked sources, breakdown by directive) for anything your policy has blocked, with CSV export.
Import/Export: Move your configuration between sites as a JSON file — handy for agencies rolling out the same policy across clients.
In-Plugin Documentation: A full read-only reference covering every setting, without leaving WP Admin.
Server Header Hardening: Removes or limits exposure of headers such as X-Powered-By and Server.
Lightweight and Fast: Uses PHP headers for broad server compatibility and minimal performance impact.
No .htaccess Editing Required: Works without modifying server configuration files.
Designed for developers and site owners who want stronger security without unnecessary complexity.
External Services
This plugin provides a Content Security Policy (CSP) builder. To assist users, it includes “Preset Buttons” that allow users to quickly add domain names to their own CSP whitelist.
This plugin DOES NOT connect to, load data from, or send data to these services automatically. The following third-party domains are referenced as presets within the admin dashboard for whitelisting purposes:
* Google Analytics (www.google-analytics.com, stats.g.doubleclick.net) – Used for tracking whitelisting. Privacy
* Google Tag Manager (www.googletagmanager.com) – Used for tag management. Privacy
* Stripe (js.stripe.com, api.stripe.com) – Used for payment processing. Privacy
* Facebook (www.facebook.com, connect.facebook.net) – Used for social embeds. Privacy
* YouTube (www.youtube.com, youtube-nocookie.com, i.ytimg.com) – Used for video embeds. Privacy
* Vimeo (player.vimeo.com) – Used for video embeds. Privacy
* Gravatar (secure.gravatar.com) – Used for user avatars. Privacy
* Google Maps (maps.google.com) – Used for map embeds. Privacy
* Google Fonts (fonts.googleapis.com, fonts.gstatic.com) – Used for web font whitelisting. Privacy
* Zendesk (assets.zendesk.com) – Used for support widget whitelisting. Privacy
