{"id":253706,"date":"2025-10-02T17:34:27","date_gmt":"2025-10-02T17:34:27","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/volixta-ssl-security-headers\/"},"modified":"2026-08-23T02:59:56","modified_gmt":"2026-08-23T02:59:56","slug":"volixta-ssl-security-headers","status":"publish","type":"plugin","link":"https:\/\/vi.wordpress.org\/plugins\/volixta-ssl-security-headers\/","author":23369681,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.3.4","stable_tag":"1.3.4","tested":"7.1","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"Volixta SSL & Security Headers","header_author":"HELLO SITE LLC","header_description":"Activate SSL\/HTTPS, apply modern Security Headers (incl. HSTS), fix mixed content, file-permissions audit, \u2014 simple & safe.","assets_banners_color":"121b2c","last_updated":"2026-08-23 02:59:56","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/www.agence-hello-site.com\/","rating":4,"author_block_rating":0,"active_installs":10,"downloads":1352,"num_ratings":4,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"volixta","date":"2025-10-02 17:45:37"},"1.0.1":{"tag":"1.0.1","author":"volixta","date":"2025-10-03 01:09:29"},"1.0.10":{"tag":"1.0.10","author":"volixta","date":"2025-11-03 15:01:13"},"1.0.2":{"tag":"1.0.2","author":"volixta","date":"2025-10-03 01:22:25"},"1.0.3":{"tag":"1.0.3","author":"volixta","date":"2025-10-03 23:15:22"},"1.0.4":{"tag":"1.0.4","author":"volixta","date":"2025-10-03 23:21:06"},"1.0.5":{"tag":"1.0.5","author":"volixta","date":"2025-10-03 23:45:26"},"1.0.6":{"tag":"1.0.6","author":"volixta","date":"2025-11-03 14:34:56"},"1.0.7":{"tag":"1.0.7","author":"volixta","date":"2025-11-03 14:44:42"},"1.0.8":{"tag":"1.0.8","author":"volixta","date":"2025-11-03 14:50:23"},"1.0.9":{"tag":"1.0.9","author":"volixta","date":"2025-11-03 14:57:55"},"1.1.0":{"tag":"1.1.0","author":"volixta","date":"2025-11-08 02:07:38"},"1.1.1":{"tag":"1.1.1","author":"volixta","date":"2025-12-07 12:12:12"},"1.1.2":{"tag":"1.1.2","author":"volixta","date":"2025-12-10 13:09:20"},"1.1.3":{"tag":"1.1.3","author":"volixta","date":"2026-03-09 00:03:03"},"1.1.4":{"tag":"1.1.4","author":"volixta","date":"2026-03-10 23:33:47"},"1.1.5":{"tag":"1.1.5","author":"volixta","date":"2026-05-20 23:59:41"},"1.1.6":{"tag":"1.1.6","author":"volixta","date":"2026-08-20 17:17:54"},"1.2.0":{"tag":"1.2.0","author":"volixta","date":"2026-08-21 20:10:04"},"1.2.1":{"tag":"1.2.1","author":"volixta","date":"2026-08-21 20:39:34"},"1.2.2":{"tag":"1.2.2","author":"volixta","date":"2026-08-21 21:04:20"},"1.3.0":{"tag":"1.3.0","author":"volixta","date":"2026-08-22 16:16:47"},"1.3.1":{"tag":"1.3.1","author":"volixta","date":"2026-08-22 17:40:23"},"1.3.2":{"tag":"1.3.2","author":"volixta","date":"2026-08-22 17:51:14"},"1.3.3":{"tag":"1.3.3","author":"volixta","date":"2026-08-23 02:26:22"},"1.3.4":{"tag":"1.3.4","author":"volixta","date":"2026-08-23 02:59:56"}},"upgrade_notice":{"1.3.4":"<p>Version 1.3.4 redesigns the Security Headers workspace for clearer status, safer advanced editing, and better keyboard and mobile navigation.<\/p>","1.3.3":"<p>Version 1.3.3 refreshes admin assets reliably and fixes unstyled Security Headers category cards.<\/p>","1.3.2":"<p>Version 1.3.2 adds direct wp-config.php safety downloads with no server-side backup storage, alongside Secure Cookie Protection, SameSite=Lax PHP session hardening, CSP Report-Only monitoring, and fail-closed safeguards around <code>.htaccess<\/code> and <code>wp-config.php<\/code> changes.<\/p>","1.2.0":"<p>Version 1.2.0 adds native Let\u2019s Encrypt certificate management, hosting-panel installation, automatic renewal, safer <code>.htaccess<\/code> recovery, improved Mixed Content tools, and a redesigned SSL and Security Headers workflow.<\/p>","1.1.3":"<p>The Security Hardening module was removed to improve stability and compatibility.<\/p>\n\n<p>Broader WordPress security and site-management features are planned for the separate <strong>Volixta Toolkit<\/strong> plugin.<\/p>\n\n<hr \/>"},"ratings":{"1":1,"2":0,"3":0,"4":0,"5":3},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3371933,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3371933,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3371933,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772\u00d7250.png":{"filename":"banner-772\u00d7250.png","revision":3371933,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.0.1","1.0.10","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9","1.1.0","1.1.1","1.1.2","1.1.3","1.1.4","1.1.5","1.1.6","1.2.0","1.2.1","1.2.2","1.3.0","1.3.1","1.3.2","1.3.3","1.3.4"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3659610,"resolution":"1","location":"assets","locale":"","width":1280,"height":737},"screenshot-10.png":{"filename":"screenshot-10.png","revision":3660876,"resolution":"10","location":"assets","locale":"","width":1280,"height":1395},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3660876,"resolution":"2","location":"assets","locale":"","width":1280,"height":727},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3660876,"resolution":"3","location":"assets","locale":"","width":1280,"height":637},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3660876,"resolution":"4","location":"assets","locale":"","width":1280,"height":1640},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3660876,"resolution":"5","location":"assets","locale":"","width":1280,"height":1237},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3660876,"resolution":"6","location":"assets","locale":"","width":1280,"height":1032},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3660876,"resolution":"7","location":"assets","locale":"","width":1280,"height":867},"screenshot-8.png":{"filename":"screenshot-8.png","revision":3660876,"resolution":"8","location":"assets","locale":"","width":1280,"height":1783},"screenshot-9.jpg":{"filename":"screenshot-9.jpg","revision":3660876,"resolution":"9","location":"assets","locale":"","width":1280,"height":2278}},"screenshots":{"1":"Guided SSL and security setup with score and safety backup","2":"HTTPS setup with certificate check and one-click redirect","3":"SSL certificate status, expiry, and certificate tools","4":"Let\u2019s Encrypt issuance, installation, and renewal","5":"SSL file management and <code>.htaccess<\/code> safety backup","6":"Mixed content scan, fixer, and cleanup tools","7":"Secure Cookie protection for WordPress authentication and PHP sessions","8":"Recommended security headers with one-click protection","9":"Advanced security headers configuration","10":"Content Security Policy configuration with enforcement and Report-Only monitoring"}},"plugin_section":[],"plugin_tags":[1908,73969,24593,153786,1536],"plugin_category":[54],"plugin_contributors":[248681],"plugin_business_model":[],"class_list":["post-253706","plugin","type-plugin","status-publish","hentry","plugin_tags-https","plugin_tags-lets-encrypt","plugin_tags-mixed-content","plugin_tags-security-headers","plugin_tags-ssl","plugin_category-security-and-spam-protection","plugin_contributors-volixta","plugin_committers-volixta"],"banners":{"banner":"https:\/\/ps.w.org\/volixta-ssl-security-headers\/assets\/banner-772\u00d7250.png?rev=3371933","banner_2x":"https:\/\/ps.w.org\/volixta-ssl-security-headers\/assets\/banner-1544x500.png?rev=3371933","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/volixta-ssl-security-headers\/assets\/icon-128x128.png?rev=3371933","icon_2x":"https:\/\/ps.w.org\/volixta-ssl-security-headers\/assets\/icon-256x256.png?rev=3371933","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/volixta-ssl-security-headers\/assets\/screenshot-1.png?rev=3659610","caption":"Guided SSL and security setup with score and safety backup"},{"src":"https:\/\/ps.w.org\/volixta-ssl-security-headers\/assets\/screenshot-2.png?rev=3660876","caption":"HTTPS setup with certificate check and one-click redirect"},{"src":"https:\/\/ps.w.org\/volixta-ssl-security-headers\/assets\/screenshot-3.png?rev=3660876","caption":"SSL certificate status, expiry, and certificate tools"},{"src":"https:\/\/ps.w.org\/volixta-ssl-security-headers\/assets\/screenshot-4.png?rev=3660876","caption":"Let\u2019s Encrypt issuance, installation, and renewal"},{"src":"https:\/\/ps.w.org\/volixta-ssl-security-headers\/assets\/screenshot-5.png?rev=3660876","caption":"SSL file management and <code>.htaccess<\/code> safety backup"},{"src":"https:\/\/ps.w.org\/volixta-ssl-security-headers\/assets\/screenshot-6.png?rev=3660876","caption":"Mixed content scan, fixer, and cleanup tools"},{"src":"https:\/\/ps.w.org\/volixta-ssl-security-headers\/assets\/screenshot-7.png?rev=3660876","caption":"Secure Cookie protection for WordPress authentication and PHP sessions"},{"src":"https:\/\/ps.w.org\/volixta-ssl-security-headers\/assets\/screenshot-8.png?rev=3660876","caption":"Recommended security headers with one-click protection"},{"src":"https:\/\/ps.w.org\/volixta-ssl-security-headers\/assets\/screenshot-9.jpg?rev=3660876","caption":"Advanced security headers configuration"},{"src":"https:\/\/ps.w.org\/volixta-ssl-security-headers\/assets\/screenshot-10.png?rev=3660876","caption":"Content Security Policy configuration with enforcement and Report-Only monitoring"}],"raw_content":"<!--section=description-->\n<p><strong>Volixta SSL &amp; Security Headers<\/strong> helps WordPress site owners configure HTTPS, manage SSL certificates, fix mixed content, and apply modern browser security without manually editing sensitive server files.<\/p>\n\n<p>Use Volixta to request free <strong>Let\u2019s Encrypt certificates<\/strong>, install supported certificates through hosting integrations, switch WordPress to HTTPS, configure <strong>301 redirects<\/strong>, and verify the certificate that visitors actually receive.<\/p>\n\n<p>Key features include:<\/p>\n\n<ul>\n<li><strong>Let\u2019s Encrypt ACME v2<\/strong> certificate requests with HTTP-01 validation.<\/li>\n<li><strong>Certificate installation<\/strong> for supported cPanel, Plesk, and DirectAdmin environments, plus downloadable files for manual installation.<\/li>\n<li><strong>Automatic renewal checks<\/strong> for eligible Volixta-managed production certificates.<\/li>\n<li><strong>HTTPS setup and redirects<\/strong> with guarded Apache\/LiteSpeed <code>.htaccess<\/code> changes and Nginx guidance.<\/li>\n<li><strong>Mixed Content tools<\/strong> including frontend checks, Deep Scan, Live Fixer, and serialization-safe database cleanup.<\/li>\n<li><strong>Security Headers<\/strong> including HSTS, CSP, CSP Report-Only, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, COOP, COEP, and CORP.<\/li>\n<li><strong>Secure Cookies<\/strong> for WordPress authentication and PHP sessions with Secure, HttpOnly, and SameSite=Lax protection.<\/li>\n<li><strong>CSP Report-Only monitoring<\/strong> with capped local reports and rate limiting.<\/li>\n<li><strong>Safety Backups<\/strong> before managed <code>.htaccess<\/code> changes. <code>wp-config.php<\/code> backups are downloaded directly to your computer and are not stored by Volixta on the server.<\/li>\n<li><strong>Site Health integration<\/strong> for important SSL, HTTPS, redirect, cookie, and header checks.<\/li>\n<li><strong>Hosting-aware guidance<\/strong> for Apache, LiteSpeed, Nginx, reverse proxies, Cloudflare, localhost, and manual certificate workflows.<\/li>\n<\/ul>\n\n<p>Volixta is designed to fail safely: it uses marked configuration blocks, verifies backups and file snapshots, and avoids overwriting unrelated <code>.htaccess<\/code> content.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>Volixta SSL &amp; Security Headers does not include analytics, usage tracking, or visitor tracking.<\/p>\n\n<p>The plugin stores the configuration required for enabled features inside your WordPress installation. When CSP Report-Only monitoring is enabled, Volixta stores a capped local history of CSP violation diagnostics. It does not store visitor IP addresses, user agents, referrers, or CSP script samples in that report history.<\/p>\n\n<p>Some actions communicate with external services when you explicitly use features that require them. CSP violation monitoring uses a local WordPress REST endpoint and does not send those reports to a third-party reporting service.<\/p>\n\n<p>Examples include:<\/p>\n\n<ul>\n<li><strong>Let\u2019s Encrypt<\/strong>: certificate requests and ACME validation.<\/li>\n<li><strong>Hosting integrations<\/strong>: configured cPanel, Plesk, or DirectAdmin connections used for certificate installation.<\/li>\n<\/ul>\n\n<p>Only information required to perform the requested operation is sent to those services.<\/p>\n\n\n\n<h3>Localization<\/h3>\n\n<p>Text domain: <code>volixta-ssl-security-headers<\/code><br \/>\nLoad path: <code>\/languages<\/code><\/p>\n\n\n\n<h3>What\u2019s Next<\/h3>\n\n<p>If you like this plugin, check out our other tools:<\/p>\n\n<ul>\n<li><p><a href=\"https:\/\/volixta.com\">VOLIXTA Booking \u2013 The All-in-One WordPress Booking Plugin<\/a><br \/>\nManage unlimited staff, services, clients, payments, and locations in one powerful system.<\/p><\/li>\n<li><p><a href=\"https:\/\/volixta.com\/volixta-security-suite\">VOLIXTA Toolkit \u2013 A collection of practical WordPress tools for configuration, maintenance, security, and site management.<\/a><\/p><\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin to <code>\/wp-content\/plugins\/<\/code> or install <strong>Volixta SSL &amp; Security Headers<\/strong> from the WordPress plugin directory.<\/li>\n<li>Activate the plugin.<\/li>\n<li>Open <strong>Volixta SSL &amp; Security<\/strong> from the WordPress admin menu.<\/li>\n<li>Follow the Guided Setup.<\/li>\n<li>Create a Safety Backup when <code>.htaccess<\/code> changes will be used.<\/li>\n<li>Detect an existing SSL certificate or request a free Let\u2019s Encrypt certificate if needed.<\/li>\n<li>Install and verify the certificate.<\/li>\n<li>Activate WordPress HTTPS and enable the HTTPS redirect.<\/li>\n<li>Check the website for mixed content.<\/li>\n<li>Apply the recommended Security Headers if appropriate for your website.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20an%20ssl%20certificate%20before%20using%20volixta%3F\"><h3>Do I need an SSL certificate before using Volixta?<\/h3><\/dt>\n<dd><p>No. Volixta can detect an existing public certificate or request a free Let\u2019s Encrypt certificate for an eligible public domain.<\/p>\n\n<p>If your hosting provider already manages SSL, you can continue using that certificate.<\/p><\/dd>\n<dt id=\"can%20volixta%20request%20a%20free%20let%E2%80%99s%20encrypt%20ssl%20certificate%3F\"><h3>Can Volixta request a free Let\u2019s Encrypt SSL certificate?<\/h3><\/dt>\n<dd><p>Yes. Volixta includes an ACME v2 client and supports Let\u2019s Encrypt certificate requests using the HTTP-01 challenge.<\/p>\n\n<p>The domain must be publicly reachable and meet the certificate authority requirements.<\/p><\/dd>\n<dt id=\"can%20volixta%20install%20the%20ssl%20certificate%20automatically%3F\"><h3>Can Volixta install the SSL certificate automatically?<\/h3><\/dt>\n<dd><p>Yes, when a supported hosting integration is configured.<\/p>\n\n<p>Volixta supports certificate installation through cPanel, Plesk, and DirectAdmin integrations.<\/p>\n\n<p>If automatic installation is unavailable, the generated certificate files remain available for manual installation.<\/p><\/dd>\n<dt id=\"can%20volixta%20renew%20ssl%20certificates%20automatically%3F\"><h3>Can Volixta renew SSL certificates automatically?<\/h3><\/dt>\n<dd><p>Yes. Eligible Volixta-managed production certificates can be checked through WP-Cron.<\/p>\n\n<p>When a certificate reaches the renewal window, Volixta can request and install a replacement when the required hosting integration is configured.<\/p><\/dd>\n<dt id=\"how%20do%20i%20activate%20https%20in%20wordpress%3F\"><h3>How do I activate HTTPS in WordPress?<\/h3><\/dt>\n<dd><p>Once a valid certificate is available, open Volixta and follow the Guided Setup or the SSL &amp; HTTPS section.<\/p>\n\n<p>Volixta can update the WordPress Home URL and Site URL to use HTTPS.<\/p><\/dd>\n<dt id=\"how%20do%20i%20force%20http%20to%20https%3F\"><h3>How do I force HTTP to HTTPS?<\/h3><\/dt>\n<dd><p>Volixta can enable a permanent 301 HTTPS redirect.<\/p>\n\n<p>On Apache and LiteSpeed, the redirect can be added inside a Volixta-managed <code>.htaccess<\/code> block.<\/p>\n\n<p>For Nginx, Volixta provides the configuration that needs to be added to the server.<\/p><\/dd>\n<dt id=\"does%20volixta%20replace%20my%20.htaccess%20file%3F\"><h3>Does Volixta replace my .htaccess file?<\/h3><\/dt>\n<dd><p>No. Volixta is designed to manage only its own marked sections inside <code>.htaccess<\/code>.<\/p>\n\n<p>For example:<\/p>\n\n<ul>\n<li><code># BEGIN Volixta HTTPS Redirect<\/code><\/li>\n<li><code># END Volixta HTTPS Redirect<\/code><\/li>\n<\/ul>\n\n<p>Rules outside Volixta-managed blocks are preserved by the managed-block writer.<\/p>\n\n<p>Sensitive operations also use backup and consistency checks. If the file cannot be modified safely, Volixta leaves it unchanged.<\/p><\/dd>\n<dt id=\"what%20is%20the%20safety%20backup%3F\"><h3>What is the Safety Backup?<\/h3><\/dt>\n<dd><p>For .htaccess changes, Volixta can create a recovery copy of the current file before managed server rules are changed.<\/p>\n\n<p>For wp-config.php changes, Volixta does not store a backup on the server. Instead, you can download the current wp-config.php directly to your computer before applying persistent Secure Cookie settings.<\/p><\/dd>\n<dt id=\"does%20volixta%20create%20automatic%20.htaccess%20backups%3F\"><h3>Does Volixta create automatic .htaccess backups?<\/h3><\/dt>\n<dd><p>Yes. Supported sensitive <code>.htaccess<\/code> operations create an automatic rollback backup before the file is changed.<\/p>\n\n<p>You can also create and download a manual Safety Backup.<\/p><\/dd>\n<dt id=\"what%20happens%20to%20.htaccess%20when%20i%20uninstall%20volixta%3F\"><h3>What happens to .htaccess when I uninstall Volixta?<\/h3><\/dt>\n<dd><p>Volixta does not intentionally delete or replace the whole <code>.htaccess<\/code> file.<\/p>\n\n<p>The uninstall process only attempts to remove Volixta-managed blocks.<\/p>\n\n<p>Before modifying an existing <code>.htaccess<\/code> file during uninstall, a verified recovery snapshot is required. If that snapshot cannot be created safely, the existing <code>.htaccess<\/code> file is left unchanged.<\/p><\/dd>\n<dt id=\"what%20is%20mixed%20content%3F\"><h3>What is mixed content?<\/h3><\/dt>\n<dd><p>Mixed content happens when an HTTPS page still loads one or more resources through HTTP.<\/p>\n\n<p>This can include images, scripts, stylesheets, fonts, or embedded resources.<\/p><\/dd>\n<dt id=\"does%20the%20mixed%20content%20scan%20modify%20my%20database%3F\"><h3>Does the Mixed Content Scan modify my database?<\/h3><\/dt>\n<dd><p>No. Frontend checks and scans do not permanently modify WordPress content.<\/p>\n\n<p>Permanent changes are made only when you explicitly use Database Cleanup.<\/p><\/dd>\n<dt id=\"is%20database%20cleanup%20safe%20with%20serialized%20wordpress%20data%3F\"><h3>Is Database Cleanup safe with serialized WordPress data?<\/h3><\/dt>\n<dd><p>Volixta handles eligible serialized WordPress values instead of performing a blind database-wide text replacement.<\/p>\n\n<p>As with any permanent database operation, keeping a normal website backup before cleanup is recommended.<\/p><\/dd>\n<dt id=\"what%20does%20the%20live%20fixer%20do%3F\"><h3>What does the Live Fixer do?<\/h3><\/dt>\n<dd><p>The Live Fixer upgrades eligible insecure resource URLs while the page is rendered.<\/p>\n\n<p>It does not permanently change the stored database values.<\/p>\n\n<p>If your rendered frontend does not contain mixed content, there is normally no need to enable it.<\/p><\/dd>\n<dt id=\"which%20security%20headers%20does%20volixta%20support%3F\"><h3>Which Security Headers does Volixta support?<\/h3><\/dt>\n<dd><p>Volixta supports common browser protections including HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, COOP, COEP, CORP, and additional advanced policies.<\/p><\/dd>\n<dt id=\"can%20security%20headers%20break%20parts%20of%20a%20website%3F\"><h3>Can Security Headers break parts of a website?<\/h3><\/dt>\n<dd><p>Strict browser policies can affect external scripts, embedded content, APIs, media, fonts, or other resources.<\/p>\n\n<p>Volixta therefore provides a Recommended configuration and keeps more technical controls in the Advanced section.<\/p>\n\n<p>Review custom policies carefully before applying them to a production website.<\/p><\/dd>\n<dt id=\"what%20does%20secure%20cookie%20protection%20do%3F\"><h3>What does Secure Cookie Protection do?<\/h3><\/dt>\n<dd><p>Secure Cookie Protection strengthens WordPress authentication and PHP session cookies when HTTPS is enabled.<\/p>\n\n<p>Volixta can enforce Secure protection for WordPress authentication cookies and configure PHP session cookies with Secure, HttpOnly, and SameSite=Lax settings.<\/p>\n\n<p>Before persistent changes are made to wp-config.php, Volixta lets you download the current file directly to your computer. The backup is not stored on the server.<\/p><\/dd>\n<dt id=\"what%20is%20csp%20report-only%20monitoring%3F\"><h3>What is CSP Report-Only monitoring?<\/h3><\/dt>\n<dd><p>CSP Report-Only lets you test a Content Security Policy without blocking website resources.<\/p>\n\n<p>Browsers report policy violations to a local Volixta endpoint so you can identify scripts, images, connections, or other resources that would be affected before enforcing the policy.<\/p>\n\n<p>Volixta keeps only a limited local report history and does not store visitor IP addresses, user agents, referrers, or script samples.<\/p><\/dd>\n<dt id=\"does%20volixta%20work%20with%20nginx%3F\"><h3>Does Volixta work with Nginx?<\/h3><\/dt>\n<dd><p>Yes.<\/p>\n\n<p>Nginx does not use <code>.htaccess<\/code>, so Volixta provides ready-to-copy configuration for supported HTTPS redirects and Security Headers instead of attempting to modify <code>.htaccess<\/code>.<\/p><\/dd>\n<dt id=\"can%20i%20use%20volixta%20locally%3F\"><h3>Can I use Volixta locally?<\/h3><\/dt>\n<dd><p>Yes.<\/p>\n\n<p>Volixta detects common local environments such as <code>localhost<\/code>, <code>.local<\/code>, and <code>.test<\/code>.<\/p>\n\n<p>A public Let\u2019s Encrypt certificate is not required locally. If you want trusted local HTTPS, Volixta provides guidance for tools such as mkcert.<\/p><\/dd>\n<dt id=\"does%20volixta%20slow%20down%20my%20website%3F\"><h3>Does Volixta slow down my website?<\/h3><\/dt>\n<dd><p>Most plugin operations run only in the WordPress admin area.<\/p>\n\n<p>Certificate issuance, hosting communication, Deep Scan, Database Cleanup, and configuration operations do not run during normal frontend requests.<\/p>\n\n<p>Only explicitly enabled frontend features, such as the PHP redirect fallback or Live Fixer, add frontend processing.<\/p><\/dd>\n<dt id=\"does%20volixta%20collect%20personal%20data%3F\"><h3>Does Volixta collect personal data?<\/h3><\/dt>\n<dd><p>Volixta does not include visitor analytics or usage tracking.<\/p>\n\n<p>Some features communicate with external services only when required for an operation you request, such as Let\u2019s Encrypt certificate issuance or a configured hosting-panel connection.<\/p>\n\n<\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.3.4 \u2013 2026-08-23<\/h4>\n\n<ul>\n<li>Redesigned the Security Headers workspace with one clear primary action, stronger status hierarchy, full-width category navigation, progress indicators, and improved responsive behavior.<\/li>\n<li>Added plain-language labels and descriptions to advanced header and CSP fields while preserving the technical header names.<\/li>\n<li>Added unsaved-change feedback and keyboard navigation for Security Headers tabs.<\/li>\n<li>Fixed critical-header warnings in the card-based advanced editor.<\/li>\n<li>Fixed the active HTTPS redirect row so its Enabled status and Disable button remain aligned on desktop and mobile.<\/li>\n<\/ul>\n\n<h4>1.3.3 \u2013 2026-08-23<\/h4>\n\n<ul>\n<li>Fixed stale admin asset caching that could leave the Security Headers category cards unstyled and display oversized SVG icons.<\/li>\n<li>Fixed the local Security Headers testing action so it now uses the PHP runtime without changing local .htaccess rules.<\/li>\n<li>Prevented runtime Security Headers and persistent Secure Cookie rules from remaining unexpectedly active after plugin deactivation.<\/li>\n<li>Completed the Security Headers reset confirmation message.<\/li>\n<\/ul>\n\n<h4>1.3.2 \u2013 2026-08-22<\/h4>\n\n<ul>\n<li>Updated readme.txt<\/li>\n<\/ul>\n\n<h4>1.3.1 \u2013 2026-08-22<\/h4>\n\n<ul>\n<li>Improved wp-config.php handling and safety.<\/li>\n<li>Improved Secure Cookie Protection reliability.<\/li>\n<li>Minor security and stability improvements.<\/li>\n<\/ul>\n\n<h4>1.3.0 \u2013 2026-08-22<\/h4>\n\n<ul>\n<li>Added Secure Cookie Protection for WordPress authentication and PHP sessions.<\/li>\n<li>Added Secure, HttpOnly, and SameSite=Lax protection for PHP session cookies.<\/li>\n<li>Added direct wp-config.php safety download before persistent Secure Cookie changes.<\/li>\n<li>Added Secure Cookie checks to WordPress Site Health.<\/li>\n<li>Added Content Security Policy enforcement and Report-Only controls.<\/li>\n<li>Added CSP Report-Only monitoring with local violation reports.<\/li>\n<li>Added privacy-focused CSP report handling with rate limiting and capped report storage.<\/li>\n<li>Redesigned Security Headers navigation with dedicated Headers and Content Security Policy sections.<\/li>\n<li>Added Secure Cookies to the SSL &amp; HTTPS tools.<\/li>\n<li>Improved .htaccess and wp-config.php safeguards for sensitive configuration changes.<\/li>\n<li>Improved Safety Backup handling for configuration changes.<\/li>\n<li>Improved uninstall cleanup and configuration-file safety.<\/li>\n<\/ul>\n\n<h4>1.2.2 \u2013 2026-08-21<\/h4>\n\n<ul>\n<li>Updated readme.txt<\/li>\n<\/ul>\n\n<h4>1.2.1 \u2013 2026-08-21<\/h4>\n\n<ul>\n<li>Fixed WordPress compatibility metadata for WordPress 7.1<\/li>\n<\/ul>\n\n<h4>1.2.0 \u2013 2026-08-21<\/h4>\n\n<p>This is a major update to Volixta SSL &amp; Security Headers.<\/p>\n\n<ul>\n<li>Added native Let\u2019s Encrypt \/ ACME certificate issuance directly from WordPress.<\/li>\n<li>Added hosting-aware SSL installation for cPanel, Plesk, and DirectAdmin.<\/li>\n<li>Added automatic renewal for eligible managed certificates.<\/li>\n<li>Added certificate validation, active-certificate detection, expiration information, and protected SSL file management.<\/li>\n<li>Added Let\u2019s Encrypt staging support and rate-limit protection with retry-time detection.<\/li>\n<li>Added manual certificate download and installation support.<\/li>\n<li>Redesigned the Guided Setup for certificate creation, installation, HTTPS activation, redirects, recovery, and Security Headers.<\/li>\n<li>Added dedicated localhost support with optional local HTTPS and mkcert guidance.<\/li>\n<li>Added <code>.htaccess<\/code> Safety Backups and automatic rollback protection.<\/li>\n<li>Added managed-block validation, concurrent-change detection, symlink refusal, backup verification, and fail-closed <code>.htaccess<\/code> editing.<\/li>\n<li>Redesigned Mixed Content tools with manual frontend verification, Deep Scan, Live Fixer only when needed, and serialization-safe Database Cleanup.<\/li>\n<li>Expanded Recommended and Advanced Security Header controls.<\/li>\n<li>Improved Apache, LiteSpeed, Nginx, reverse-proxy, and hosting compatibility.<\/li>\n<li>Improved SSL, certificate, server, and hosting diagnostics.<\/li>\n<li>Improved mobile responsiveness and admin UX across the plugin.<\/li>\n<li>Improved security checks, escaping, sanitization, SQL handling, and WordPress.org compatibility.<\/li>\n<li>Fixed multiple edge cases and regression issues discovered during the 1.2.0 development audit.<\/li>\n<\/ul>\n\n<h4>1.1.6 \u2013 2026-08-20<\/h4>\n\n<ul>\n<li>Tested up to WordPress 7.1.<\/li>\n<\/ul>\n\n<h4>1.1.5 \u2013 2026-05-21<\/h4>\n\n<ul>\n<li>Tested up to WordPress 7.0.<\/li>\n<\/ul>\n\n<h4>1.1.4 \u2013 2026-03-11<\/h4>\n\n<ul>\n<li>Updated readme.txt.<\/li>\n<\/ul>\n\n<h4>1.1.3 \u2013 2026-03-09<\/h4>\n\n<ul>\n<li>Removed the Security Hardening module to improve stability and compatibility.<\/li>\n<\/ul>\n\n<h4>1.1.2 \u2013 2025-12-10<\/h4>\n\n<ul>\n<li>Added Security Hardening controls for Secure and HttpOnly cookies.<\/li>\n<li>Added directory-indexing protection.<\/li>\n<li>Added user-enumeration protection.<\/li>\n<li>Improved PHPCS compliance and sanitization.<\/li>\n<li>Updated the uninstall routine.<\/li>\n<li>Improved the Security Hardening interface.<\/li>\n<li>Updated readme.txt.<\/li>\n<\/ul>\n\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>Tested up to WordPress 6.9.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Improved SSL detection and code compliance.<\/li>\n<\/ul>\n\n<h4>1.0.10<\/h4>\n\n<ul>\n<li>Updated readme.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<\/ul>","raw_excerpt":"Set up WordPress SSL, HTTPS redirects, Let\u2019s Encrypt certificates, mixed content fixes, and security headers from one guided interface.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/253706","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=253706"}],"author":[{"embeddable":true,"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/volixta"}],"wp:attachment":[{"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=253706"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=253706"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=253706"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=253706"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=253706"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=253706"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}