New to Translating WordPress? Read through our Translator Handbook to get started. Hide
| Prio | Original string | Translation | — |
|---|---|---|---|
| ↑ | Headers Security Advanced & HSTS WP | You have to log in to add a translation. | Details |
Original untranslated |
|||
| ↑ | Best all-in-one WordPress security plugin, uses HTTP & HSTS response headers to avoid vulnerabilities: XSS, injection, clickjacking. Force HTTP/HTTPS. | You have to log in to add a translation. | Details |
Original untranslated
Best all-in-one WordPress security plugin, uses HTTP & HSTS response headers to avoid vulnerabilities: XSS, injection, clickjacking. Force HTTP/HTTPS.
CommentShort description. You have to log in to edit this translation. |
|||
| Your site stays fully protected. All headers keep working. You lose Shield features (dashboard, advisor, alerts, analytics) and revert to the free version. Nothing breaks. | You have to log in to add a translation. | Details | |
Original untranslated
Your site stays fully protected. All headers keep working. You lose Shield features (dashboard, advisor, alerts, analytics) and revert to the free version. Nothing breaks.
CommentFound in faq paragraph. You have to log in to edit this translation. |
|||
| When writing CSP directives: | You have to log in to add a translation. | Details | |
Original untranslated
When writing CSP directives:
CommentFound in faq paragraph. You have to log in to edit this translation. |
|||
| Enter the report URL from your monitoring service (Sentry, Report URI, URIports, or Datadog) into the CSP Report URI field in Settings. The plugin adds the report-uri directive to your CSP header automatically. | You have to log in to add a translation. | Details | |
Original untranslated
Enter the report URL from your monitoring service (Sentry, Report URI, URIports, or Datadog) into the CSP Report URI field in Settings. The plugin adds the report-uri directive to your CSP header automatically.
CommentFound in faq paragraph. You have to log in to edit this translation. |
|||
| CSP tells browsers which resources can load on your page. Anything not explicitly allowed is blocked. It is the strongest protection against XSS attacks. | You have to log in to add a translation. | Details | |
Original untranslated
CSP tells browsers which resources can load on your page. Anything not explicitly allowed is blocked. It is the strongest protection against XSS attacks.
CommentFound in faq paragraph. You have to log in to edit this translation. |
|||
| Only if your entire domain (including all subdomains) works over HTTPS. Preload is hardcoded in browsers and difficult to undo. Removal takes months. Test thoroughly first. | You have to log in to add a translation. | Details | |
Original untranslated
Only if your entire domain (including all subdomains) works over HTTPS. Preload is hardcoded in browsers and difficult to undo. Removal takes months. Test thoroughly first.
CommentFound in faq paragraph. You have to log in to edit this translation. |
|||
| Minimum for preload: 31536000 (1 year). Recommended: 63072000 (2 years). Start with 86400 (1 day) to test, then increase. | You have to log in to add a translation. | Details | |
Original untranslated
Minimum for preload: 31536000 (1 year). Recommended: 63072000 (2 years). Start with 86400 (1 day) to test, then increase.
CommentFound in faq paragraph. You have to log in to edit this translation. |
|||
| HTTP Strict Transport Security tells browsers to always use HTTPS. Even if someone types http://, the browser upgrades to https:// automatically. Prevents protocol downgrade attacks. | You have to log in to add a translation. | Details | |
Original untranslated
HTTP Strict Transport Security tells browsers to always use HTTPS. Even if someone types http://, the browser upgrades to https:// automatically. Prevents protocol downgrade attacks.
CommentFound in faq paragraph. You have to log in to edit this translation. |
|||
| Rarely. If another plugin sets the same headers, you may get duplicates. Use the "Resolve duplicate headers" checkboxes in Settings to fix this. | You have to log in to add a translation. | Details | |
Original untranslated
Rarely. If another plugin sets the same headers, you may get duplicates. Use the "Resolve duplicate headers" checkboxes in Settings to fix this.
CommentFound in faq paragraph. You have to log in to edit this translation. |
|||
| Your site needs all 6 scored headers present: Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and Permissions-Policy. The plugin configures all of these automatically. | You have to log in to add a translation. | Details | |
Original untranslated
Your site needs all 6 scored headers present: Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and Permissions-Policy. The plugin configures all of these automatically.
CommentFound in faq paragraph. You have to log in to edit this translation. |
|||
| Yes. Cloudflare passes through headers set by WordPress. If you also set headers in Cloudflare dashboard, use the "Resolve duplicate headers" option in Settings to avoid duplicates. | You have to log in to add a translation. | Details | |
Original untranslated
Yes. Cloudflare passes through headers set by WordPress. If you also set headers in Cloudflare dashboard, use the "Resolve duplicate headers" option in Settings to avoid duplicates.
CommentFound in faq paragraph. You have to log in to edit this translation. |
|||
| Yes. Compatible with WP Super Cache, W3 Total Cache, LiteSpeed Cache, WP Rocket, and others. | You have to log in to add a translation. | Details | |
Original untranslated
Yes. Compatible with WP Super Cache, W3 Total Cache, LiteSpeed Cache, WP Rocket, and others.
CommentFound in faq paragraph. You have to log in to edit this translation. |
|||
| Yes. The PHP method (wp_headers filter) works on any server. The .htaccess method is Apache-only, but the plugin automatically uses the PHP method on other servers. | You have to log in to add a translation. | Details | |
Original untranslated
Yes. The PHP method (wp_headers filter) works on any server. The .htaccess method is Apache-only, but the plugin automatically uses the PHP method on other servers.
CommentFound in faq paragraph. You have to log in to edit this translation. |
|||
| No. Headers add less than 1KB to each response. The plugin uses WordPress native hooks and Apache .htaccess. Zero database queries at page load for visitors. | You have to log in to add a translation. | Details | |
Original untranslated
No. Headers add less than 1KB to each response. The plugin uses WordPress native hooks and Apache .htaccess. Zero database queries at page load for visitors.
CommentFound in faq paragraph. You have to log in to edit this translation. |
|||
Export as
Comment
Plugin name.