Title: EssentialHeaders
Author: Alex Hedström
Published: <strong>ऑगस्ट 14, 2026</strong>
Last modified: ऑगस्ट 28, 2026

---

प्लगइन शोधा

![](https://ps.w.org/essentialheaders/assets/banner-772x250.png?rev=3646718)

![](https://ps.w.org/essentialheaders/assets/icon-256x256.png?rev=3646718)

# EssentialHeaders

 [Alex Hedström](https://profiles.wordpress.org/alexhedstrom/) कडून

[डाउनलोड करा](https://downloads.wordpress.org/plugin/essentialheaders.1.0.2.zip)

 * [तपशील](https://mr.wordpress.org/plugins/essentialheaders/#description)
 * [पुनरावलोकने](https://mr.wordpress.org/plugins/essentialheaders/#reviews)
 *  [इंस्टॉलेशन](https://mr.wordpress.org/plugins/essentialheaders/#installation)
 * [डेव्हलोपमेंट](https://mr.wordpress.org/plugins/essentialheaders/#developers)

 [समर्थन](https://wordpress.org/support/plugin/essentialheaders/)

## वर्णन

EssentialHeaders is a focused WordPress plugin that attaches the HTTP security headers
browsers expect, so protection is not left to chance or buried in server config.

Under Settings  EssentialHeaders you get three tabs:

 * Headers — overview of which headers are enabled and will be sent
 * Settings — toggles and editable values for each header
 * About — plugin info

Headers covered:

 * Content-Security-Policy (CSP)
 * Strict-Transport-Security (HSTS)
 * X-Frame-Options
 * X-Content-Type-Options
 * Referrer-Policy
 * Permissions-Policy
 * X-Powered-By (remove it or replace its value)

Safer headers are enabled with sensible defaults. CSP starts off with a strict baseline,
so you can test and allow only the sources your site needs before enabling it. Headers
apply to public site responses (pages, feeds, and the login screen)—not wp-admin,
AJAX, REST, GraphQL, or XML-RPC. HSTS is only sent over HTTPS. Default HSTS uses
max-age only; add includeSubDomains yourself when every subdomain is ready.

## स्थापना

 1. Upload the `essentialheaders` folder to the `/wp-content/plugins/` directory.
 2. Activate the plugin through the Plugins menu in WordPress.
 3. Open Settings  EssentialHeaders to review and configure headers.

## नेहमी विचारले जाणारे प्रश्न

### Will this break my site?

The default set is conservative. Content-Security-Policy is off by default because
a strict CSP can block scripts or styles your theme needs. Enable CSP when you are
ready to tune it.

### Does HSTS work on HTTP?

No. Strict-Transport-Security is only sent when the visitor reaches the site over
HTTPS.

### Does the login screen get these headers?

Yes. The login screen is treated as a public response. wp-admin, AJAX, REST, GraphQL,
and XML-RPC are excluded, so dashboards and APIs are not broken by a strict CSP.

### Does this change site content?

No. The plugin only stores its own options and manages HTTP response headers on 
public responses.

### Can X-Powered-By always be removed?

EssentialHeaders removes PHP- and WordPress-managed instances at the latest applicable
WordPress header hook. Another callback running afterward, a reverse proxy, or a
web server can add the header again; remove it at that layer as well.

## समीक्षा

ह्या प्लगइनसाठी कोणतेही समीक्षण नाही.

## योगदानकर्ते आणि विकसक

“EssentialHeaders” हे मुक्त स्रोत सॉफ्टवेअर आहे. पुढील लोक या प्लगइनच्या निर्मितीत
योगदान केले आहे.

योगदानकर्ते

 *   [ Alex Hedström ](https://profiles.wordpress.org/alexhedstrom/)

[भाषांतर करा “EssentialHeaders” तुमच्या भाषेत.](https://translate.wordpress.org/projects/wp-plugins/essentialheaders)

### विकासातील आग्रह?

[कोड ब्राउझ करा](https://plugins.trac.wordpress.org/browser/essentialheaders/), 
[SVN संग्रहालय](https://plugins.svn.wordpress.org/essentialheaders/) तपासा, किंवा
[विकास लॉग](https://plugins.trac.wordpress.org/log/essentialheaders/) च्या [RSS](https://plugins.trac.wordpress.org/log/essentialheaders/?limit=100&mode=stop_on_copy&format=rss)
द्वारे सदस्यता घ्या.

## बदलांची यादी

#### 1.0.2

 * Add: manage X-Powered-By by removing it when its value is blank or replacing 
   it with a custom value.
 * Improve: enforce managed header replacement at the latest applicable WordPress
   header hooks.

#### 1.0.1

 * Fix: always send security headers on front-end HTML even when the request Accept
   header prefers JSON. Skipping those requests let page caches store header-less
   responses and broke scanner results after cache warm-up.

#### 1.0.0

 * Initial release.

## मेटा

 *  आवृत्ती **1.0.2**
 *  शेवटचा अद्यतन **1 महिना पूर्वी**
 *  सक्रिय स्थापना **20+**
 *  वर्डप्रेस आवृत्ती ** 6.3 किंवा मोठा **
 *  परीक्षित केले आहे **7.1.2**
 *  PHP आवृत्ती ** 7.4 किंवा मोठा **
 *  भाषा
 * [English (US)](https://wordpress.org/plugins/essentialheaders/)
 * टॅग्ज:
 * [csp](https://mr.wordpress.org/plugins/tags/csp/)[headers](https://mr.wordpress.org/plugins/tags/headers/)
   [hsts](https://mr.wordpress.org/plugins/tags/hsts/)[http](https://mr.wordpress.org/plugins/tags/http/)
   [security](https://mr.wordpress.org/plugins/tags/security/)
 *  [प्रगत दृश्य](https://mr.wordpress.org/plugins/essentialheaders/advanced/)

## मूल्यांकन

अजून कोणतीही पुनरावलोकने सबमिट केलेली नाहीत.

[आपला अभिप्राय](https://wordpress.org/support/plugin/essentialheaders/reviews/#new-post)

[सर्व पुनरावलोकने पहा](https://wordpress.org/support/plugin/essentialheaders/reviews/)

## योगदानकर्ते

 *   [ Alex Hedström ](https://profiles.wordpress.org/alexhedstrom/)

## समर्थन

काहीतरी सांगायचं आहे का? मदतीची आवश्यकता आहे का?

 [समर्थन फोरम पहा](https://wordpress.org/support/plugin/essentialheaders/)