HomeHow ToProtect HTTP Headers in WordPress

Protecting HTTP headers in WordPress

Below we will see how you can secure (as much as possible) the WordPress headers you use. Secure HTTP headers will help you strengthen WordPress's defense against attacks by closing some vulnerabilities.

There are a total of 6 HTTP headers that you can implement on your website by adding the following code to the functions.php file located in the themes folder.

WordPress

Content Security Policy or (CSP)

CSP helps protect against XSS attacks and uses whitelists for allowed content sources, such as scripts, CSS, and images. A secure Content Security Policy can prevent the browser from loading malicious scripts and other elements.

Unfortunately, there is no one-size-fits-all code for all websites. Before you create your own CSP you should evaluate the resources that actually need to be loaded. Of course, to create your own policy you should read, if you want a policy based on your own requirements.

Your CSP can be added to the functions.php file.

You can try adding the following line:

header('Content-Security-Policy: default-src \'self\' \'unsafe-inline\' \'unsafe-eval\' https: data:');

What does it do? The above CSP allows all file types from your own domain, “self.” “unsafe-inline” allows all your own (inline) css & scripts and “unsafe-eval” says that any unsafe dynamic code, like JS, is allowed. The “https” and “data” tags allow resources to be loaded only over HTTPS. If you are not using HTTPS, leave it plain HTTP.

X-Frame-Options

This header helps prevent Clickjacking by indicating to a browser that it cannot load the page in a frame or iframe.

Add the following policy to your functions.php like this:

header('X-Frame-Options: SAMEORIGIN');

X-XSS-Protection and X-Content-Type-Options

X-XSS-Protection helps protect against cross-site scripting (XSS) attacks, and X-Content-Type-Options instructs IE not to sniff mime types. This header is needed to prevent attacks related to mime-sniffing.

Add again to your functions.php:

header('X-XSS-Protection: 1; mode=block'); header('X-Content-Type-Options: nosniff');

HTTP Strict Transport Security (HSTS)

HSTS is a way for the server to tell the browser that it should only communicate with the server over HTTPS. If you are not using HTTPS, skip the step below.

Add the following code to functions.php:

header('Strict-Transport-Security:max-age=31536000; includeSubdomains; preload');

Adding Cookies with HTTPOnly and Secure flag in WordPress

This command tells the browser to trust the cookie only from the server and that the cookie is accessible over secure SSL channels.

Add this to your functions.php file:

@ini_set('session.cookie_httponly', true); @ini_set('session.cookie_secure', true); @ini_set('session.use_only_cookies', true);

All of the above together:

header('Content-Security-Policy: default-src \'self\' \'unsafe-inline\' \'unsafe-eval\' https: data:'); header('X-Frame-Options: SAMEORIGIN'); header('X-XSS-Protection: 1; mode=block'); header('X-Content-Type-Options: nosniff'); header('Strict-Transport-Security:max-age=31536000; includeSubdomains; preload'); @ini_set('session.cookie_httponly', true); @ini_set('session.cookie_secure', true); @ini_set('session.use_only_cookies', true);

WordPress

Another way to secure HTTP headers is through the .htaccess file. Below is the code you can add to the .htaccess file located in your WordPress /:

Header set Strict-Transport-Security "max-age=31536000; includeSubDomains" Header set X-XSS-Protection "1; mode=block" Header set X-Frame-Options "sameorigin" Header set X-Content-Type-Options "nosniff" Header set Content-Security-Policy "default-src 'self' 'unsafe-inline' 'unsafe-eval' https:data:";

Alternatively, you can use various plugins that are available by searching for “Security Headers” in the WordPress repositories.

You can test the HTTP security headers you added from the https://securityheaders.io.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS