Volixta SSL & Security Headers

Description

Volixta SSL & Security Headers helps WordPress site owners configure HTTPS, manage SSL certificates, fix mixed content, and apply modern browser security without manually editing sensitive server files.

Use Volixta to request free Let’s Encrypt certificates, install supported certificates through hosting integrations, switch WordPress to HTTPS, configure 301 redirects, and verify the certificate that visitors actually receive.

Key features include:

  • Guided Setup Wizard that checks your site first, then guides you step by step through SSL certificate setup, HTTPS activation, redirects, Security Headers, optional alerts, and a final status review.
  • Beginner-first Overview with advanced certificate, DNS, HSTS, CSP, Secure Cookies, Mixed Content, file, backup, and recovery tools available when needed.
  • Free SSL certificates with Let’s Encrypt ACME v2 using automatic HTTP-01 or manual DNS-01 validation, including wildcard certificates.
  • Automatic SSL installation for supported cPanel, Plesk, and DirectAdmin environments, with hosting account connection directly from the Setup Wizard and downloadable certificate files for manual installation.
  • Automatic renewal checks for eligible HTTP-01 Volixta-managed production certificates, with clear renewal status and guidance for manual DNS-01 certificates.
  • HTTPS setup and redirects with guarded Apache/LiteSpeed .htaccess changes and clear Nginx guidance.
  • Mixed Content tools including frontend checks, Deep Scan, Live Fixer, and serialization-safe database cleanup.
  • Security Headers including HSTS, CSP, CSP Report-Only, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, COOP, COEP, and CORP.
  • Secure Cookies for WordPress authentication and PHP sessions with Secure, HttpOnly, and SameSite=Lax protection.
  • Safety Backups before managed .htaccess changes. wp-config.php backups are downloaded directly to your computer and are not stored by Volixta on the server.
  • Certificate and protection alerts for upcoming certificate expiry, recent renewal failures, and protection regressions.
  • HSTS preload assistant that verifies the public Strict-Transport-Security response before reporting preload readiness, without submitting your domain to an external preload service.
  • Hosting-aware guidance for Apache, LiteSpeed, Nginx, reverse proxies, Cloudflare, localhost, and manual certificate workflows.
  • Local development support with a simplified Setup Wizard that avoids unsupported production-only actions while keeping compatible local HTTPS workflows available.

Volixta is designed to fail safely: it uses marked configuration blocks, verifies backups and file snapshots, and avoids overwriting unrelated .htaccess content.

External Services

Volixta does not send telemetry or usage analytics. External connections happen only when an administrator explicitly uses a feature that requires them.

  • Let’s Encrypt / ISRG — used when you request or renew a certificate. The requested domain names and ACME protocol data are sent to Let’s Encrypt. The ACME contact email you provide is sent to ISRG with the account request. See https://letsencrypt.org/repository/ and https://letsencrypt.org/privacy/.
  • Hosting control panels — cPanel, Plesk, or DirectAdmin are contacted only after you explicitly configure the integration and request certificate installation. Certificate/private-key material is sent only to the hosting endpoint you configured or that Volixta safely detected.
  • Your own public website/DNS — certificate, HTTP-01, DNS-01, HTTPS, header, and Mixed Content checks may connect to the site/domain you are administering. These checks do not send data to Volixta.

Privacy

Volixta SSL & Security Headers does not include analytics, usage tracking, or visitor tracking.

The plugin stores the configuration required for enabled features inside your WordPress installation.

Some actions communicate with external services when you explicitly use features that require them.

Examples include:

  • Let’s Encrypt: certificate requests and ACME validation.
  • Hosting integrations: configured cPanel, Plesk, or DirectAdmin connections used for certificate installation.

Only information required to perform the requested operation is sent to those services.

Localization

Text domain: volixta-ssl-security-headers
Load path: /languages

What’s Next

If you like this plugin, check out our other tools:

Screenshots

Installation

  1. Upload the plugin to /wp-content/plugins/ or install Volixta SSL & Security Headers from the WordPress plugin directory.
  2. Activate the plugin.
  3. Open Volixta SSL & Security from the WordPress admin menu.
  4. Follow the Guided Setup.
  5. Create a Safety Backup when .htaccess changes will be used.
  6. Detect an existing SSL certificate or request a free Let’s Encrypt certificate if needed.
  7. Install and verify the certificate.
  8. Activate WordPress HTTPS and enable the HTTPS redirect.
  9. Check the website for mixed content.
  10. Apply the recommended Security Headers if appropriate for your website.

FAQ

Do I need an SSL certificate before using Volixta?

No. Volixta can detect an existing public certificate or, after you choose to do so, request a free Let’s Encrypt certificate for an eligible public domain.

Can Volixta renew certificates automatically?

Yes, for eligible Volixta-managed HTTP-01 certificates. Automatic renewal is off by default and starts only after an administrator explicitly enables it. Manual DNS-01 certificates require a new DNS confirmation.

Can Volixta install certificates automatically?

Yes, when you explicitly configure a supported cPanel, Plesk, or DirectAdmin integration. Otherwise you can download the generated certificate files for manual installation.

Does Volixta replace my .htaccess file?

No. Volixta manages only its own marked blocks and uses safety checks before sensitive writes. If a change cannot be made safely, the existing file is preserved.

Does the Mixed Content Scan modify my database?

No. Scans are read-only. Permanent database changes happen only after you explicitly start Database Cleanup and confirm that you have a restore point.

Can Security Headers break a website?

Very strict policies can affect scripts, embeds, fonts, APIs, or media. Volixta therefore offers a compatibility-oriented Recommended profile and keeps advanced policies available for manual configuration.

Does Volixta work with Nginx?

Yes. Because Nginx does not use .htaccess, Volixta provides configuration guidance instead of trying to edit .htaccess.

Does Volixta collect analytics or usage data?

No. Volixta does not include visitor analytics, admin telemetry, or usage tracking. Network connections used by optional certificate, hosting, and diagnostic features are documented in External Services below.

Reviews

August 27, 2026 1 reply
I had regular issues with earlier versions (prior to 1.1.2), so stopped using it on most sites, but after updating on the one site I still had it installed on – this latest version (currently 1.3.4) is so much better (I hadn't updated since 1.1.2 so improvements were probably already there before 1.3.4 😉 ) UI has improved as well, and haven't run into any issues – working great so far, so it looks like I'll be adding it back to my other sites again 😉 Thanks so much for this really useful and convenient plugin!
Read all 3 reviews

Contributors & Developers

“Volixta SSL & Security Headers” is open source software. The following people have contributed to this plugin.

Contributors

Changelog

1.5.0 – 2026-10-02

  • Added a new beginner-friendly Setup Wizard that guides certificate setup, HTTPS activation, redirects, Security Headers, alerts, and final verification step by step.
  • Added Recommended and Manual Security Headers configuration directly in the wizard, with explicit user choices and no preselected protection options.
  • Integrated Let’s Encrypt HTTP-01 and DNS-01 certificate flows into the wizard, including wildcard support, installation guidance, and certificate verification before continuing.
  • Added hosting account integration directly inside the Setup Wizard for cPanel, Plesk, and DirectAdmin, with clear connection status, secure credential handling, and automatic SSL installation when supported.
  • Improved automatic certificate installation UX by showing hosting availability before installation and providing a clear “Connect hosting account” flow when no hosting integration is configured.
  • Simplified the Setup Wizard for local development environments by hiding or disabling unsupported certificate, redirect, Security Headers, HSTS, public scan, and alert actions while keeping compatible local HTTPS workflows available.
  • Added stronger server-side safeguards to prevent unsupported SSL and Security Header actions from being triggered on local development environments.
  • Improved Setup Wizard navigation feedback with immediate loading states, contextual button labels such as “Continuing…”, “Going back…”, “Saving…”, and “Installing…”, double-click protection, and improved accessibility feedback.
  • Redesigned the main administration experience with a clearer Overview, simplified navigation, cleaner status presentation, and improved responsive behavior.
  • Improved mobile administration layouts with better action hierarchy, responsive navigation tabs, reduced duplicate actions, and more compact status presentation.
  • Improved action button hierarchy throughout the administration interface so primary, secondary, and safety-related actions are visually easier to distinguish.
  • Refined the Setup Wizard header and responsive visual styling for better readability on smaller screens.
  • Added a Volixta Analytics Lite presentation page, optional wizard recommendation, and native WordPress.org installation action, hidden when Analytics Lite is already installed.
  • Suppressed unrelated WordPress and third-party admin notices only on Volixta SSL & Security Headers screens.
  • Improved Files & Paths presentation and layout.
  • Hardened wizard permissions, nonces, Multisite access, certificate downloads, private-key temporary-file cleanup, progression checks, input validation, hosting integration validation, and server-side authorization.
  • Improved uninstall cleanup for wizard state, version markers, SSL storage, certificates, backups, scheduled events, and Volixta-managed configuration blocks.
  • Made Let’s Encrypt automatic renewal explicitly opt-in and disabled legacy preselected renewal during migration unless explicit consent exists.
  • Added a conservative versioned migration path from 1.4.x that preserves existing SSL, HTTPS redirect, Security Headers, Secure Cookies, alerts, certificates, hosting integrations, Mixed Content settings, and backups without forcing the new wizard.
  • Improved WordPress.org compliance by keeping Tested up to only in readme.txt, documenting external services, and loading admin JavaScript and CSS through WordPress enqueue APIs.

1.4.0 – 2026-09-23

  • Added DNS-01 validation and wildcard certificate support.
  • Added certificate expiry, renewal failure, and protection regression email notifications.
  • Improved SSL certificate generation, renewal, storage, and file management.
  • Improved compatibility and security across Apache, LiteSpeed, Nginx, OpenResty, and WordPress Multisite.
  • Hardened ACME storage, .htaccess, wp-config.php, configuration backups, permissions, and filesystem operations.
  • Improved Security Headers, HTTPS, Secure Cookies, and Mixed Content handling.
  • Improved plugin cleanup, migration, and uninstall reliability.
  • Fixed various SSL, configuration, compatibility, and stability issues.

1.3.4 – 2026-08-23

  • Redesigned the Security Headers workspace with one clear primary action, stronger status hierarchy, full-width category navigation, progress indicators, and improved responsive behavior.
  • Added plain-language labels and descriptions to advanced header and CSP fields while preserving the technical header names.
  • Added unsaved-change feedback and keyboard navigation for Security Headers tabs.
  • Fixed critical-header warnings in the card-based advanced editor.
  • Fixed the active HTTPS redirect row so its Enabled status and Disable button remain aligned on desktop and mobile.

1.3.3 – 2026-08-23

  • Fixed stale admin asset caching that could leave the Security Headers category cards unstyled and display oversized SVG icons.
  • Fixed the local Security Headers testing action so it now uses the PHP runtime without changing local .htaccess rules.
  • Prevented runtime Security Headers and persistent Secure Cookie rules from remaining unexpectedly active after plugin deactivation.
  • Completed the Security Headers reset confirmation message.

1.3.2 – 2026-08-22

  • Updated readme.txt

1.3.1 – 2026-08-22

  • Improved wp-config.php handling and safety.
  • Improved Secure Cookie Protection reliability.
  • Minor security and stability improvements.

1.3.0 – 2026-08-22

  • Added Secure Cookie Protection for WordPress authentication and PHP sessions.
  • Added Secure, HttpOnly, and SameSite=Lax protection for PHP session cookies.
  • Added direct wp-config.php safety download before persistent Secure Cookie changes.
  • Added Secure Cookie checks to WordPress Site Health.
  • Added Content Security Policy enforcement and Report-Only controls.
  • Added CSP Report-Only monitoring with local violation reports.
  • Added privacy-focused CSP report handling with rate limiting and capped report storage.
  • Redesigned Security Headers navigation with dedicated Headers and Content Security Policy sections.
  • Added Secure Cookies to the SSL & HTTPS tools.
  • Improved .htaccess and wp-config.php safeguards for sensitive configuration changes.
  • Improved Safety Backup handling for configuration changes.
  • Improved uninstall cleanup and configuration-file safety.

1.2.2 – 2026-08-21

  • Updated readme.txt

1.2.1 – 2026-08-21

  • Fixed WordPress compatibility metadata for WordPress 7.1

1.2.0 – 2026-08-21

This is a major update to Volixta SSL & Security Headers.

  • Added native Let’s Encrypt / ACME certificate issuance directly from WordPress.
  • Added hosting-aware SSL installation for cPanel, Plesk, and DirectAdmin.
  • Added automatic renewal for eligible managed certificates.
  • Added certificate validation, active-certificate detection, expiration information, and protected SSL file management.
  • Added Let’s Encrypt staging support and rate-limit protection with retry-time detection.
  • Added manual certificate download and installation support.
  • Redesigned the Guided Setup for certificate creation, installation, HTTPS activation, redirects, recovery, and Security Headers.
  • Added dedicated localhost support with optional local HTTPS and mkcert guidance.
  • Added .htaccess Safety Backups and automatic rollback protection.
  • Added managed-block validation, concurrent-change detection, symlink refusal, backup verification, and fail-closed .htaccess editing.
  • Redesigned Mixed Content tools with manual frontend verification, Deep Scan, Live Fixer only when needed, and serialization-safe Database Cleanup.
  • Expanded Recommended and Advanced Security Header controls.
  • Improved Apache, LiteSpeed, Nginx, reverse-proxy, and hosting compatibility.
  • Improved SSL, certificate, server, and hosting diagnostics.
  • Improved mobile responsiveness and admin UX across the plugin.
  • Improved security checks, escaping, sanitization, SQL handling, and WordPress.org compatibility.
  • Fixed multiple edge cases and regression issues discovered during the 1.2.0 development audit.

1.1.6 – 2026-08-20

  • Tested up to WordPress 7.1.

1.1.5 – 2026-05-21

  • Tested up to WordPress 7.0.

1.1.4 – 2026-03-11

  • Updated readme.txt.

1.1.3 – 2026-03-09

  • Removed the Security Hardening module to improve stability and compatibility.

1.1.2 – 2025-12-10

  • Added Security Hardening controls for Secure and HttpOnly cookies.
  • Added directory-indexing protection.
  • Added user-enumeration protection.
  • Improved PHPCS compliance and sanitization.
  • Updated the uninstall routine.
  • Improved the Security Hardening interface.
  • Updated readme.txt.

1.1.1

  • Tested up to WordPress 6.9.

1.1.0

  • Improved SSL detection and code compliance.

1.0.10

  • Updated readme.

1.0.0

  • Initial release.