• News
  • Startups
  • Marketing
  • Ad Campaigns
  • Tech & Tools
  • How-to Guides
  • Insights
  • Culture & Media
Sunday, May 18, 2025
  • Login
Digital Boom
  • News
  • Startups
  • Marketing
  • Ad Campaigns
  • Tech & Tools
  • How-to Guides
  • Insights
  • Culture & Media
No Result
View All Result
  • News
  • Startups
  • Marketing
  • Ad Campaigns
  • Tech & Tools
  • How-to Guides
  • Insights
  • Culture & Media
No Result
View All Result
Digital Boom
No Result
View All Result

WordPress SSL Alert: Missing Security Headers in .htaccess File

Ahmed Maher by Ahmed Maher
November 25, 2020
in Guides & Tutorials
2
A A
Wordpress Alert: Missing Security Headers in .htaccess File

Wordpress Alert: Missing Security Headers in .htaccess File

41
SHARES
203
VIEWS

WordPress website owners started to see a new alert with recommended actions in the WordPress site’s health security (if you have Simple SSL plugin active).

What caused the new health alert?

The new alert in the “Site heath” section appeared after updating the Really Simple SSL plugin.

In this article, we will fix the following missing security headers using the .htaccess file.

  • HTTP Strict Transport Security
  • Content Security Policy: Upgrade Insecure Requests
  • X-XSS protection
  • X-Content Type Options
  • Referrer-Policy
  • X-Frame-Options
  • Expect-CT

How to add the new security headers to the .htaccess file?

We’ve put together a single code to be added to your .htaccess file that will fix all your security headers issues, and then this alert will disappear accordingly.

Note: please make sure that you have access to your cPanel before implementing any of these lines in your htaccess file, because if something went wrong you will lose access to your wordpress admin dashboard.

Copy and paste the below code at the end of your .htaccess.

<ifModule mod_headers.c>
Header always set Content-Security-Policy “upgrade-insecure-requests;”
</IfModule>

# Security Headers
<IfModule mod_headers.c>
Header set X-XSS-Protection “1; mode=block”
Header set X-Frame-Options “SAMEORIGIN”
Header set X-Content-Type-Options “nosniff”
Header always set Strict-Transport-Security “max-age=63072000; includeSubDomains”
# Header set Content-Security-Policy …
Header set Referrer-Policy “same-origin”
</IfModule>

<IfModule mod_headers.c>
Header set Expect-CT enforce,max-age=2592000,report-uri=”https://foo.example/report”
</IfModule>

Tool to verify http response headers

To verify your http response headers fixes, you can test your url using on of the following tools/methods:

  • Security Headers
  • Redbot.org
  • or you can install a free wordpress plugin called “http headers plugin“

Happy Fixing!

Ahmed Maher

Ahmed Maher

Editor in Chief, focuses on marketing trends, educational content, no-code web development like webflow and framer, marketing tips and growth hacking tactics.

Related Posts

How to include current URL in a Webflow form?
Guides & Tutorials

Include current CMS item URL in Webflow forms

November 14, 2023
221
How Positive Thinking Can Turbo Charge Your Career
Guides & Tutorials

How Positive Thinking Can Turbo Charge Your Career

July 5, 2023
205
8 Mind-Blowing Websites to Boost Creativity You Probably Didn't Know Existed
Guides & Tutorials

8 Mind-Blowing Websites to Boost Creativity You Probably Didn’t Know Existed

July 4, 2023
202
How to Copy and paste between devices from your Mac/iPhone
Guides & Tutorials

How to enable copy and paste between Apple devices?

November 24, 2022
202
How to increase the time limit to unsend emails on iPhone?
Guides & Tutorials

How to increase the delay time to unsend emails on iPhone?

September 19, 2022
202
10 hidden settings in iOS 16 that you need to try today
Guides & Tutorials

10 hidden settings in iOS 16 that you need to try today

September 19, 2022
202

LATEST

Google Updates Its Iconic "G" Logo for the First Time in Nearly a Decade
Creative & Design

Google Updates Its Iconic ‘G’ Logo for the First Time in Nearly a Decade

by Ahmed Maher
May 16, 2025
324
The Evolution of Influencer Marketing: From Royal Endorsements to Social Media Powerhouses
Marketing

The Evolution of Influencer Marketing: From Royal Endorsements to Social Media Powerhouses

by Ahmed Maher
May 15, 2025
46.1k
How to Change Where Screenshots Are Saved on Mac (And Master Every Shortcut)
Productivity

How to Change Where Screenshots Are Saved on Mac (And Master Every Shortcut)

by Ahmed Maher
May 15, 2025
60.1k
Inside Radi Farms: The Agritech Startup Reshaping Egypt’s Food Supply Chain
Startups

Inside Radi Farms: The Agritech Startup Reshaping Egypt’s Food Supply Chain

by Ahmed Maher
April 7, 2025
773
Anthropic Launches Web Search for Claude AI Assistant
Tech & Tools

Anthropic Launches Web Search for Claude AI Assistant

by Ahmed Maher
March 20, 2025
206
  • Partners
  • Privacy Policy
  • About us
  • Contact us

© 2025 Digital Boom, Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • About us
  • Become a Digital Boom Author
  • Checkout
  • Checkout
  • Contact us
  • Contributing Writers
  • Digital Boom Home
  • Digital Tools
  • Join us
  • Live News Headlines
  • Login/Register
  • Login/Register
  • My account
  • My account
  • Partners
  • Plans
  • Privacy Policy
  • Staff
  • Terms
  • Terms of Use

© 2025 Digital Boom, Inc.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.