Hi @aussiesj @horrormoviesgr ,
Thanks for reporting this, and sorry for the trouble. The cause is confirmed and it’s on our side: since 5.3.4 the plugin sent the security headers only through PHP, so pages served straight from a cache went out without them. That’s what securityheaders.com is showing you. The A+ in the plugin dashboard was misleading for the same reason, and that’s being corrected too.
I’m releasing 5.4.1 of the licensed plugin, which resolves this. I’ll post here as soon as it’s available on your account, and it will also come through the normal licensed update.
Aussiesj: once you’re on 5.4.1, could you check a page served from WP Rocket’s cache and let me know whether the headers are there? That would help me confirm the fix on that setup.
Andrea
Hi,
It’s better with the latest update, but there is still a cache issue regarding the Content-Security-Policy.
H Andrea,
Thank you for the updated plugin. I have now got a A rating on securityheaders.com and it was an instant fix once updated. As the comment above, there is still a cache issue regarding the Content-Security-Policy which I am sure will be corrected in the next update.
I am genuinely thankful for your response to my problem. Thanks Andrea!