Title: EssentialHeaders
Author: Alex Hedström
Published: <strong>ઓગસ્ટ 14, 2026</strong>
Last modified: ઓગસ્ટ 16, 2026

---

પ્લગીન શોધો

![](https://ps.w.org/essentialheaders/assets/banner-772x250.png?rev=3646718)

![](https://ps.w.org/essentialheaders/assets/icon-256x256.png?rev=3646718)

# EssentialHeaders

 [Alex Hedström](https://profiles.wordpress.org/alexhedstrom/) દ્વારા

[ડાઉનલોડ](https://downloads.wordpress.org/plugin/essentialheaders.1.0.1.zip)

 * [વિગતો](https://gu.wordpress.org/plugins/essentialheaders/#description)
 * [સમીક્ષાઓ](https://gu.wordpress.org/plugins/essentialheaders/#reviews)
 *  [સ્થાપન](https://gu.wordpress.org/plugins/essentialheaders/#installation)
 * [ડેવલપમેન્ટ](https://gu.wordpress.org/plugins/essentialheaders/#developers)

 [સપોર્ટ](https://wordpress.org/support/plugin/essentialheaders/)

## વર્ણન

EssentialHeaders is a focused WordPress plugin that attaches the HTTP security headers
browsers expect, so protection is not left to chance or buried in server config.

Under Settings  EssentialHeaders you get three tabs:

 * Headers — overview of which headers are enabled and will be sent
 * Settings — toggles and editable values for each header
 * About — plugin info

Headers covered:

 * Content-Security-Policy (CSP)
 * Strict-Transport-Security (HSTS)
 * X-Frame-Options
 * X-Content-Type-Options
 * Referrer-Policy
 * Permissions-Policy

Safer headers ship enabled with sensible defaults. CSP starts off so you can adopt
it deliberately. Headers apply to public site responses (pages, feeds, and the login
screen)—not wp-admin, AJAX, REST, GraphQL, or XML-RPC. HSTS is only sent over HTTPS.
Default HSTS uses max-age only; add includeSubDomains yourself when every subdomain
is ready.

## સ્થાપન

 1. Upload the `essentialheaders` folder to the `/wp-content/plugins/` directory.
 2. Activate the plugin through the Plugins menu in WordPress.
 3. Open Settings  EssentialHeaders to review and configure headers.

## એફએક્યુ (FAQ)

### Will this break my site?

The default set is conservative. Content-Security-Policy is off by default because
a strict CSP can block scripts or styles your theme needs. Enable CSP when you are
ready to tune it.

### Does HSTS work on HTTP?

No. Strict-Transport-Security is only sent when the visitor reaches the site over
HTTPS.

### Does the login screen get these headers?

Yes. The login screen is treated as a public response. wp-admin, AJAX, REST, GraphQL,
and XML-RPC are excluded so dashboards and APIs are not broken by a strict CSP.

### Does this change site content?

No. The plugin only stores its own options and adds HTTP response headers on public
responses.

## સમીક્ષાઓ

આ પ્લગઇન માટે કોઈ સમીક્ષાઓ નથી.

## ફાળો આપનાર & ડેવલપર્સ

આ ઓપન સોર્સ સોફ્ટવેર છે. નીચેના લોકો એ આ પ્લગિન માટે ફાળો આપ્યો છે.

ફાળો આપનારા

 *   [ Alex Hedström ](https://profiles.wordpress.org/alexhedstrom/)

[“EssentialHeaders” ને તમારી ભાષામાં અનુવાદ કરો.](https://translate.wordpress.org/projects/wp-plugins/essentialheaders)

### વિકાસમાં રસ ધરાવો છો?

[કોડ બ્રાઉઝ કરો](https://plugins.trac.wordpress.org/browser/essentialheaders/), 
જોવો[અસ્વીએન રેપોઝિટરીમાંથી](https://plugins.svn.wordpress.org/essentialheaders/),
અથવા સબ્સ્ક્રાઇબ કરો[ડેવલપમેન્ટ](https://plugins.trac.wordpress.org/log/essentialheaders/)
દ્વારા[આરઅસઅસ](https://plugins.trac.wordpress.org/log/essentialheaders/?limit=100&mode=stop_on_copy&format=rss).

## ચેન્જલૉગ

#### 1.0.1

 * Fix: always send security headers on front-end HTML even when the request Accept
   header prefers JSON. Skipping those requests let page caches store header-less
   responses and broke scanner results after cache warm-up.

#### 1.0.0

 * Initial release.

## મેટા

 *  વર્ઝન **1.0.1**
 *  છેલ્લી અપડેટ: **4 દિવસ પહેલા**
 *  સક્રિય સ્થાપનો: **10+**
 *  વર્ડપ્રેસ વર્ઝન ** 6.3 અથવા ઉચ્ચતર **
 *  **7.1** સુધી પરીક્ષણ કર્યું
 *  PHP સંસ્કરણ ** 7.4 અથવા ઉચ્ચતર **
 *  ભાષા
 * [English (US)](https://wordpress.org/plugins/essentialheaders/)
 * ટૅગ્સ:
 * [csp](https://gu.wordpress.org/plugins/tags/csp/)[hardening](https://gu.wordpress.org/plugins/tags/hardening/)
   [headers](https://gu.wordpress.org/plugins/tags/headers/)[http](https://gu.wordpress.org/plugins/tags/http/)
   [security](https://gu.wordpress.org/plugins/tags/security/)
 *  [વિગતવાર દૃશ્ય](https://gu.wordpress.org/plugins/essentialheaders/advanced/)

## પૉઇન્ટ્સ

હજુ સુધી કોઈ સમીક્ષા સબમિટ કરવામાં આવી નથી.

[તમારા અભિપ્રાયો](https://wordpress.org/support/plugin/essentialheaders/reviews/#new-post)

[બધા  સમીક્ષાઓ જુઓ](https://wordpress.org/support/plugin/essentialheaders/reviews/)

## ફાળો આપનારા

 *   [ Alex Hedström ](https://profiles.wordpress.org/alexhedstrom/)

## સપોર્ટ

કંઈક કહેવું છે? મદદ જોઈએ છે?

 [આધાર ફોરમ જુઓ](https://wordpress.org/support/plugin/essentialheaders/)