Security Headers & Caching
Security Headers & Caching is a comprehensive WordPress plugin that helps protect your website by implementing essential HTTP security headers and optimizing performance through intelligent caching mechanisms. Compatible with all hosting providers including Aruba, SiteGround, Bluehost, and more. Key Features Easy Configuration – Simple admin interface to enable/disable security headers Multiple Security Headers – Comprehensive security header support Smart Caching – Configurable cache duration for better performance Universal Compatibility – Works with all hosting providers No Conflicts – Compatible with popular security and caching plugins Translation Ready – Full internationalization support Security Headers Included X-Powered-By – Removes server technology information to prevent targeted attacks Content-Security-Policy (CSP) – Controls which resources can be loaded to prevent XSS attacks Strict-Transport-Security (HSTS) – Forces HTTPS connections for enhanced security X-XSS-Protection – Enables XSS filtering in older browsers X-Frame-Options – Prevents clickjacking attacks by controlling iframe embedding X-Content-Type-Options – Prevents MIME type sniffing Referrer-Policy – Controls how much referrer information is shared Permissions-Policy – Controls browser features and APIs Caching Features Configurable cache duration (seconds) Automatic cache headers management Compatible with CDN services No conflict with existing cache plugins Why Security Headers Matter Security headers are HTTP response headers that tell your browser how to behave when handling your website’s content. They help protect against: Cross-Site Scripting (XSS) attacks Clickjacking attempts Code injection attacks MIME type sniffing Protocol downgrade attacks And much more… Developer Friendly The plugin provides filters for developers to customize headers: shc_security_headers – Filter to modify security headers array Test Your Security After installing and configuring the plugin, test your site’s security at: * Security Headers * Mozilla Observatory Privacy This plugin does not collect, store, or transmit any user data. It only modifies HTTP response headers sent by your server. Developer Documentation Filters shc_security_headers Modify the security headers before they are sent. add_filter( 'shc_security_headers', function( $headers ) { // Add custom header $headers['X-Custom-Header'] = 'custom-value'; // Modify existing header $headers['X-Frame-Options'] = 'DENY'; return $headers; } ); Constants SHC_VERSION – Plugin version number SHC_PLUGIN_DIR – Plugin directory path SHC_PLUGIN_URL – Plugin directory URL SHC_PLUGIN_BASENAME – Plugin basename Support For support, feature requests, or bug reports, please visit: * Plugin Website Credits Developed by Studio Be4 – Web Design & Development Agency License This plugin is licensed under the GPLv2 or later.
Top keywords
- headers20×5.46%
- security18×4.92%
- security headers12×3.28%
- attacks6×1.64%
- shc6×1.64%
- caching5×1.37%
- cache4×1.09%
- support4×1.09%
- compatible3×0.82%
- controls3×0.82%
- header3×0.82%
- http3×0.82%
SQLite Object Cache
A persistent object cache helps your site perform well. This one uses the widely available SQLite3 extension, and optionally the igbinary and APCu extensions to php. Many hosting services offer those extensions, and they are easy to install on a server you control. What is this about? It’s about making your site’s web server perform better. An object cache does that by reducing the workload on your MariaDB or MySQL database. This is not a page cache; these persistent objects go into a different kind of cache. These objects aren’t chunks of web pages ready for people to view in their browsers, they are data objects for use by the WordPress software. Caches are ubiquitous in computing, and WordPress has its own caching subsystem. Caches contain short-term copies of the results of expensive database lookups or computations, and allow software to use the copy rather than repeating the expensive operation. This plugin (like other object-caching plugins) extends WordPress’s caching subsystem to save those short-term copies from page view to page view. WordPress’s cache happens to be a memoization cache. Without a persistent object cache, every WordPress page view must use your MariaDB or MySQL database server to retrieve everything about your site. When a user requests a page, WordPress starts from scratch and loads everything it needs from your database server. Only then can it deliver content to your user. With a persistent object cache, WordPress immediately loads much of the information it needs. This lightens the load on your database server and delivers content to your users faster. Who should use this? If your site runs on a single web server machine, and that server provides the SQLite3 and igbinary extensions to php, this plugin will almost certainly make your site work faster. And if that server provides the APCu extension, this plugin uses it too. Some hosting providers offer redis cache servers. If your provider offers redis, it may be a good choice. You can use it via the Redis Object Cache plugin. Sites using redis have one SQL database and another non-SQL storage server: redis. Other hosting providers offer memcached, which has the Memcached Object Cache plugin. And some large multipurpose cache plugins, such as the LiteSpeed Cache, also offer object caching based on one of those cache server software packages. The cache-server approach to object caching comes into its own when you have multiple load-balanced web server machines handling your site. SQLite doesn’t work correctly in a multiple-web-server environment. But, for single-server site configurations, SQLite, possibly assisted by APCu, performs well. And the vast majority of sites are single-server. APCu APCu is an in-memory storage medium. It lets php programs, like WordPress, store data in shared memory so it’s very fast to retrieve when needed. If APCu is available on your host server, you can configure this plugin to use it. It reduces the typical cache lookup time to one-fifth or less of the SQLite lookup time, which is itself a few tens of microseconds. Performance counts, especially on busy web sites. Please look at Installation to learn how to configure this plugin to use APCu. The plugin works fast without it, and faster with it. WP-CLI: Even if APCu is in use, caching with SQLite is necessary when your web site uses WP-CLI, because WP-CLI programs do not have access to the APCu cache. This plugin writes all cached data both to APCu and to SQLite and makes sure the two are synchronized. WP-CLI You can control this plugin via WP-CLI once you activate it. Please type this command into your shell for details. wp help sqlite-object-cache Credits Thanks to Till Krüss. His Redis Object Cache plugin serves as a model for this one. And thanks to Ari Stathopoulos and Jonny Harris for reviewing this. Props to Matt Jones for finding and fixing a bug that appeared on a heavily loaded system. Thanks to Massimo Villa for testing help, and to nickchomey for a comprehensive code review. All defects are, of course, entirely the author’s responsibility. And thanks to Jetbrains for the use of their software development tools, especially PhpStorm. It’s hard to imagine how a plugin like this one could be developed without PhpStorm’s tools for exploring epic code bases like WordPress’s. How can I learn more about making my WordPress site more efficient? We offer several plugins to help with your site’s database efficiency. You can read about them here.