{"id":343181,"date":"2026-07-31T21:52:17","date_gmt":"2026-07-31T21:52:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/http-headers-advanced\/"},"modified":"2026-08-02T07:03:31","modified_gmt":"2026-08-02T07:03:31","slug":"jeelsh-http-headers","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/jeelsh-http-headers\/","author":23535294,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.2","stable_tag":"1.0.2","tested":"7.0.2","requires":"5.0","requires_php":"7.4","requires_plugins":null,"header_name":"Jeelsh HTTP Headers","header_author":"Jeelsh","header_description":"Configure and manage HTTP security headers, including CSP, HSTS, Referrer-Policy, X-Frame-Options, and Permissions-Policy, from WordPress.","assets_banners_color":"","last_updated":"2026-08-02 07:03:31","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/github.com\/jeelsh\/http-headers","header_author_uri":"https:\/\/github.com\/jeelsh","rating":0,"author_block_rating":0,"active_installs":0,"downloads":127,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"jeelshy","date":"2026-07-31 21:51:44"},"1.0.1":{"tag":"1.0.1","author":"jeelshy","date":"2026-08-01 05:25:17"},"1.0.2":{"tag":"1.0.2","author":"jeelshy","date":"2026-08-02 07:03:31"}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3630539,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3630539,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.0.1","1.0.2"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[262246],"plugin_tags":[19966,34310,32637,153786,1173],"plugin_category":[],"plugin_contributors":[274091],"plugin_business_model":[],"class_list":["post-343181","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-csp","plugin_tags-hsts","plugin_tags-http-headers","plugin_tags-security-headers","plugin_tags-wordpress-security","plugin_contributors-jeelshy","plugin_committers-jeelshy"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/jeelsh-http-headers\/assets\/icon-128x128.png?rev=3630539","icon_2x":"https:\/\/ps.w.org\/jeelsh-http-headers\/assets\/icon-256x256.png?rev=3630539","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Jeelsh HTTP Headers gives you an easy-to-use interface inside your WordPress dashboard to set HTTP response headers that improve your site's security and compliance.<\/p>\n\n<p>With this plugin you can configure:<\/p>\n\n<ul>\n<li>Content-Security-Policy (CSP) headers<\/li>\n<li>HTTP Strict Transport Security (HSTS)<\/li>\n<li>Referrer-Policy<\/li>\n<li>X-Frame-Options<\/li>\n<li>Permissions-Policy<\/li>\n<li>X-Content-Type-Options<\/li>\n<li>X-Permitted-Cross-Domain-Policies<\/li>\n<li>Your own custom headers<\/li>\n<\/ul>\n\n<p>All settings are validated and applied safely without touching your site's core files.<\/p>\n\n<h3>Features<\/h3>\n\n<ul>\n<li>Intuitive React-based admin panel<\/li>\n<li>Predefined security headers with helpful descriptions<\/li>\n<li>Custom header support<\/li>\n<li>Settings validation before saving<\/li>\n<li>Works out of the box with pre-built assets<\/li>\n<li>No external service dependencies by default<\/li>\n<\/ul>\n\n<h3>Requirements<\/h3>\n\n<ul>\n<li>WordPress 5.0 or higher<\/li>\n<li>PHP 7.4 or higher<\/li>\n<\/ul>\n\n<h3>External Services<\/h3>\n\n<p>This plugin does not connect to any third-party service by default. The following items are documented for transparency:<\/p>\n\n<ul>\n<li><p>CSP report-uri: If you configure a report-uri in the CSP settings, the browser will send CSP violation reports to the user-provided URL. The plugin does not provide or operate that endpoint; the site administrator chooses and controls it. By default the report-uri field is empty and no reports are sent.<\/p><\/li>\n<li><p>Example domains in settings fields: Inputs such as https:\/\/example.com and https:\/\/api.example.com use IANA-reserved example domains as placeholders only. The plugin does not connect to them.<\/p><\/li>\n<li><p>GitHub documentation link: The admin sidebar includes a link to https:\/\/github.com\/jeelsh\/http-headers. It opens only when a user clicks it. GitHub is operated by GitHub, Inc.; for terms and privacy, see https:\/\/docs.github.com\/en\/site-policy\/github-terms\/github-terms-of-service and https:\/\/docs.github.com\/en\/site-policy\/privacy-policies\/github-privacy-statement.<\/p><\/li>\n<li><p>Support email link: The admin sidebar includes a mailto:jeelsh@protonmail.com link. It opens the user's email client; the plugin does not send any data.<\/p><\/li>\n<li><p>WordPress REST API and admin-ajax: Saving and validating settings uses the site's own WordPress REST API endpoints and admin-ajax.php. These are same-site, internal communications.<\/p><\/li>\n<\/ul>\n\n<h3>Privacy<\/h3>\n\n<p>Jeelsh HTTP Headers does not collect, store, or transmit any personal data on its own. All header configuration is stored in your WordPress database. The only optional external communication is a CSP report-uri that you, the site administrator, choose to configure.<\/p>\n\n<h3>Support<\/h3>\n\n<p>For help, documentation, and bug reports, visit the GitHub repository: https:\/\/github.com\/jeelsh\/http-headers<\/p>\n\n<p>For direct support, you can also email jeelsh@protonmail.com.<\/p>\n\n<h3>Development<\/h3>\n\n<p>The plugin's user interface is built with React. The source code is available for review on GitHub: https:\/\/github.com\/jeelsh\/http-headers<\/p>\n\n<p>For build and development instructions, see <code>DEVELOPMENT.md<\/code>.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin files to the <code>\/wp-content\/plugins\/jeelsh-http-headers<\/code> directory, or install the plugin through the WordPress Plugins screen.<\/li>\n<li>Activate the plugin through the Plugins screen in WordPress.<\/li>\n<li>Open <strong>Jeelsh HTTP Headers<\/strong> from the WordPress administration menu to configure your headers.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20the%20plugin%20gpl-compatible%3F\"><h3>Is the plugin GPL-compatible?<\/h3><\/dt>\n<dd><p>Yes. Jeelsh HTTP Headers is licensed under the GNU General Public License v2.0 or later.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20require%20a%20third-party%20service%3F\"><h3>Does the plugin require a third-party service?<\/h3><\/dt>\n<dd><p>No, not by default. Header configuration and validation run within your WordPress installation. For details on optional user-initiated connections, see the External Services section below.<\/p><\/dd>\n<dt id=\"can%20i%20add%20my%20own%20custom%20headers%3F\"><h3>Can I add my own custom headers?<\/h3><\/dt>\n<dd><p>Yes. The plugin includes a custom headers section where you can define additional HTTP headers.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.2 (2026-08-02)<\/h4>\n\n<ul>\n<li>Fixed header injection not applying on wp-admin and wp-login.php.<\/li>\n<li>Added a check for Apache's mod_headers before allowing the .htaccess injection method, with automatic fallback to PHP-based injection.<\/li>\n<li>Fixed a 404 on bundled font assets caused by absolute asset URLs in the compiled CSS.<\/li>\n<li>Finished the rebrand from \"HTTP Headers Advanced\" to \"Jeelsh HTTP Headers\" internal keys and translation files.<\/li>\n<li>Admin panel visual adjustments and new UI components.<\/li>\n<\/ul>\n\n<h4>1.0.1 (2026-07-31)<\/h4>\n\n<ul>\n<li>Improved the admin panel display.<\/li>\n<li>Improved plugin documentation.<\/li>\n<\/ul>\n\n<h4>1.0.0 (2026-07-31)<\/h4>\n\n<ul>\n<li>First release.<\/li>\n<li>Configure Content-Security-Policy (CSP) headers to define which content sources the browser is allowed to load.<\/li>\n<li>Configure HTTP Strict Transport Security (HSTS) to enforce HTTPS connections across the site.<\/li>\n<li>Configure Referrer-Policy to control how much referrer information is shared with requests.<\/li>\n<li>Configure X-Frame-Options to prevent clickjacking by restricting iframe embedding.<\/li>\n<li>Configure Permissions-Policy to restrict which browser features can be used on the site.<\/li>\n<li>Configure X-Content-Type-Options to prevent MIME-type sniffing by browsers.<\/li>\n<li>Configure X-Permitted-Cross-Domain-Policies to manage cross-domain Adobe Flash\/Reader behavior.<\/li>\n<li>Add custom HTTP headers to cover any additional site requirement.<\/li>\n<li>Validate settings before saving to ensure headers are applied with correct and safe values.<\/li>\n<\/ul>","raw_excerpt":"Configure advanced HTTP security headers for your WordPress site.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/343181","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=343181"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/jeelshy"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=343181"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=343181"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=343181"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=343181"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=343181"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=343181"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}