Security Headers for WordPress: HSTS, CSP and Friends
A practical, non-breaking rollout order for HSTS, CSP, and the other browser-enforced security headers, plus how to verify each one actually took effect.
All posts in this stream, newest first.
A practical, non-breaking rollout order for HSTS, CSP, and the other browser-enforced security headers, plus how to verify each one actually took effect.
The padlock looks the same no matter which certificate sits behind it. Here is what DV, OV, and EV actually verify, and why automated free certificates are the right call for nearly every WordPress site.