Beplus Security Headers & Script Auditor

Beplus Security Headers & Script Auditor

Details
View on WordPress

Beplus Security Headers & Script Auditor gives WordPress site owners three things in one screen:

  1. Security header toggles — enable X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Strict-Transport-Security, Permissions-Policy, Content-Security-Policy (with an optional report-only mode), and the legacy X-XSS-Protection header, each with sensible defaults.
  2. A scanner — fetches your homepage, or optionally your whole site (up to 200 of your most recently published posts/pages), and lists every external script, stylesheet, image, iframe, and form target it finds, plus a count of inline scripts/styles.
  3. Recommendations you control — every finding is listed as a checkbox row; uncheck anything you don’t want, and the Content-Security-Policy preview updates live. Apply the checked rows to the CSP field with one click, review it, then press Save. Nothing is ever sent automatically.

There’s also a repeatable table for adding any other custom response header your site needs.

Why use this plugin

  • No external service calls, tracking, or phone-home behaviour — the scan only requests pages on your own site.
  • Every setting is sanitized on save, and header values are stripped of line breaks to prevent HTTP header injection.
  • Sensible, conservative defaults: only X-Frame-Options, X-Content-Type-Options, and Referrer-Policy are enabled out of the box. HSTS, Permissions-Policy, CSP, and X-XSS-Protection are opt-in since they can affect how your site behaves and should be reviewed first.

Details

Plugin code:
beplus-security-headers-script-auditor
Plugin version:
1.0.0
Author:
Outdated:
No
WP version:
6.0 or higher
PHP version:
7.4 or higher
Test up to WP version:
7.1
Total installations:
0
Last updated:
2026-08-19
Rating:
Times rated:
0
content-security-policy
csp
headers
http-headers
security