Security Headers & Caching
Security Headers & Caching is a comprehensive WordPress plugin that helps protect your website by implementing essential HTTP security headers and optimizing performance through intelligent caching mechanisms. Compatible with all hosting providers including Aruba, SiteGround, Bluehost, and more. Key Features Easy Configuration – Simple admin interface to enable/disable security headers Multiple Security Headers – Comprehensive security header support Smart Caching – Configurable cache duration for better performance Universal Compatibility – Works with all hosting providers No Conflicts – Compatible with popular security and caching plugins Translation Ready – Full internationalization support Security Headers Included X-Powered-By – Removes server technology information to prevent targeted attacks Content-Security-Policy (CSP) – Controls which resources can be loaded to prevent XSS attacks Strict-Transport-Security (HSTS) – Forces HTTPS connections for enhanced security X-XSS-Protection – Enables XSS filtering in older browsers X-Frame-Options – Prevents clickjacking attacks by controlling iframe embedding X-Content-Type-Options – Prevents MIME type sniffing Referrer-Policy – Controls how much referrer information is shared Permissions-Policy – Controls browser features and APIs Caching Features Configurable cache duration (seconds) Automatic cache headers management Compatible with CDN services No conflict with existing cache plugins Why Security Headers Matter Security headers are HTTP response headers that tell your browser how to behave when handling your website’s content. They help protect against: Cross-Site Scripting (XSS) attacks Clickjacking attempts Code injection attacks MIME type sniffing Protocol downgrade attacks And much more… Developer Friendly The plugin provides filters for developers to customize headers: shc_security_headers – Filter to modify security headers array Test Your Security After installing and configuring the plugin, test your site’s security at: * Security Headers * Mozilla Observatory Privacy This plugin does not collect, store, or transmit any user data. It only modifies HTTP response headers sent by your server. Developer Documentation Filters shc_security_headers Modify the security headers before they are sent. add_filter( 'shc_security_headers', function( $headers ) { // Add custom header $headers['X-Custom-Header'] = 'custom-value'; // Modify existing header $headers['X-Frame-Options'] = 'DENY'; return $headers; } ); Constants SHC_VERSION – Plugin version number SHC_PLUGIN_DIR – Plugin directory path SHC_PLUGIN_URL – Plugin directory URL SHC_PLUGIN_BASENAME – Plugin basename Support For support, feature requests, or bug reports, please visit: * Plugin Website Credits Developed by Studio Be4 – Web Design & Development Agency License This plugin is licensed under the GPLv2 or later.
Top keywords
- headers20×5.46%
- security18×4.92%
- security headers12×3.28%
- attacks6×1.64%
- shc6×1.64%
- caching5×1.37%
- cache4×1.09%
- support4×1.09%
- compatible3×0.82%
- controls3×0.82%
- header3×0.82%
- http3×0.82%
SpinupWP
This plugin ensures that the SpinupWP page cache is cleared when your site’s content changes. Not using SpinupWP yet? Sign up here. SpinupWP is a modern server control panel that’s here to help you implement best practices for every server you spin up. Designed for WordPress. This companion plugin should be installed on sites created using SpinupWP to allow the page cache to be cleared when your site’s content changes. Not using SpinupWP yet? Sign up here. Any Provider We support DigitalOcean, Linode, AWS, and any other provider. If your server has an IP address, you can connect SpinupWP. It does need to be a fresh install of Ubuntu though. Latest & Greatest Software SpinupWP will install the latest stable versions of Nginx, PHP, MySQL/MariaDB, and Redis from the standard apt-get repos. No who-knows-what-they-did custom builds of packages. Disconnect from SpinupWP in the future and you can still keep your packages up-to-date with apt-get upgrade. Automatic Security Updates SpinupWP will configure your server to install security updates as soon as they are available to reduce the likelihood of a software vulnerability putting your server at risk. Free SSL/TLS Certificates Serving your site over HTTPS is essential these days, not only for security, but to take advantage of the performance improvements of HTTP/2 as well. When you add a site to SpinupWP, a free Let’s Encrypt SSL/TLS certificate will be acquired, installed, and configured for your site. And SpinupWP will handle certificate renewals as well, so you hardly need to think about certificates. Cache All the Things One of the keys to a great performing WordPress site is caching. All sites are set up with Redis object caching to greatly reduce database requests. And with the check of a box you can enable full-page caching to serve pages lightning fast without even hitting PHP. Git Push-to-Deploy Developers! Developers! Developers! Add a git repository to your SpinupWP site and simply push to master to deploy your code. GitHub, Bitbucket, or a custom git repo will work. You can also configure a build script to run some tasks on the server after deployment is complete. Error Logs WordPress doesn’t enable error logging by default. Probably because the log is saved to a publicly accessible directory and can quickly balloon to take up a lot of hard drive space. SpinupWP enables error logs by default but stores them in a safe place and makes sure they’re rotated regularly like other server logs. Security Security Security Each server provisioned by SpinupWP is security-hardened from the word go. SSH login is disabled for the root user (you login with your user and use sudo instead). The firewall only allows connections to Nginx and SSH and failed attempts are monitored and blocked when the reach a threshold. Nginx is configured to defend against XSS, clickjacking, MIME sniffing, and other attacks. Software security updates are installed automatically. Scheduled Posts Published on Schedule For every site you add via SpinupWP, a server-side cron job will be configured to make sure that your WordPress site’s cron is executed every minute, as it should be. WP-CLI Preloaded If you love WP-CLI (we do! ❤) you’ll be very pleased to find it available on the command line the first time you login to your server. Security Isolation for Sites For each site that you add to your server via SpinupWP, a new system user is created for that site. All site files are owned by the site user and a PHP-FPM pool is configured to run as that user as well. Each site only has access to its files and so if only one site has a security vulnerability and gets infected with malware for example, only the files for that one site can be infected. SFTP Access for Your Clients If you’re hosting a site for someone else, you can easily give them SFTP/SSH access to just that site. And because of the security isolation between sites, they will only have access to files for that site. Professional Guidance & Best Practices SpinupWP will actively point you in the right direction and offer suggestions for maintaining your server. And because it provides detailed feedback about the operations it runs on your server, you can learn what is happening with your server. New release of Ubuntu just came out, should I upgrade? We’ll add a notice to the app about that, why we don’t recommend upgrading your existing servers, and how you can spin up a new server with the new release of Ubuntu and migrate your sites to that server instead. Should I install Varnish to improve page caching performance? We’ve benchmarked Varnish and Nginx FastCGI Cache performed better. Varnish would add complexity too, so one less moving part is another reason. Much of the time SpinupWP will suggest things that you may not have even thought of. Email deliverability for example. SpinupWP will strongly encourage you to configure an email sending plugin for the best email deliverability. SpinupWP’s guidance is especially helpful for those new to managing a server, but can also help those who’ve been at it a while, providing transparency to our decisions. Scheduled Backups of Site Files & Database All server providers (DigitalOcean, Linode, etc) offer automated backups of your entire server for a fee. These services are great and we highly recommend having backups of your whole server. But what happens if some media or data was deleted by accident from your WordPress site? You’re not going to restore your entire server just to get that data back. That’s where site backups come in. Site backups are full backups of your site files (media, themes, and plugins) and database. They allow you to easily restore a single site or just some files or data from a single site. With SpinupWP’s site backups, you choose your preferred provider to stash your backups whether that’s Amazon S3, DigitalOcean Spaces, or Google Cloud Storage. You plug in your account details and SpinupWP will send your site backups there in an easy-to-see format. Teamwork Makes the Dream Work Create a new team account, invite a member of your team, and allow them to spin up their own servers. Or just only allow them to add sites, the permissions you give them is up to you. Features Page cache purging Persistent object caching Ensures debug.log files aren’t saved in a publicly-accessible location