• Partners
  • Privacy Policy
  • About Us
  • Contact Us
  • Submit an Article
Saturday, June 21, 2025
Digital Boom
  • News
  • Startups
  • Marketing
    • Digital Advertising
    • Insights
  • Campaigns
  • Tech
  • Guides
  • Market Watch
  • More
    • Careers
    • Ramadan Specials
    • Culture
    • Travel
    • Glossary
No Result
View All Result
  • News
  • Startups
  • Marketing
    • Digital Advertising
    • Insights
  • Campaigns
  • Tech
  • Guides
  • Market Watch
  • More
    • Careers
    • Ramadan Specials
    • Culture
    • Travel
    • Glossary
No Result
View All Result
Digital Boom
No Result
View All Result
Home Guides

WordPress SSL Alert: Missing Security Headers in .htaccess File

Ahmed Maher by Ahmed Maher
November 25, 2020
in Guides
11
Wordpress Alert: Missing Security Headers in .htaccess File

Wordpress Alert: Missing Security Headers in .htaccess File

356
VIEWS

WordPress website owners started to see a new alert with recommended actions in the WordPress site’s health security (if you have Simple SSL plugin active).

What caused the new health alert?

The new alert in the “Site heath” section appeared after updating the Really Simple SSL plugin.

In this article, we will fix the following missing security headers using the .htaccess file.

  • HTTP Strict Transport Security
  • Content Security Policy: Upgrade Insecure Requests
  • X-XSS protection
  • X-Content Type Options
  • Referrer-Policy
  • X-Frame-Options
  • Expect-CT

How to add the new security headers to the .htaccess file?

We’ve put together a single code to be added to your .htaccess file that will fix all your security headers issues, and then this alert will disappear accordingly.

Note: please make sure that you have access to your cPanel before implementing any of these lines in your htaccess file, because if something went wrong you will lose access to your wordpress admin dashboard.

Copy and paste the below code at the end of your .htaccess.

<ifModule mod_headers.c>
Header always set Content-Security-Policy “upgrade-insecure-requests;”
</IfModule>

# Security Headers
<IfModule mod_headers.c>
Header set X-XSS-Protection “1; mode=block”
Header set X-Frame-Options “SAMEORIGIN”
Header set X-Content-Type-Options “nosniff”
Header always set Strict-Transport-Security “max-age=63072000; includeSubDomains”
# Header set Content-Security-Policy …
Header set Referrer-Policy “same-origin”
</IfModule>

<IfModule mod_headers.c>
Header set Expect-CT enforce,max-age=2592000,report-uri=”https://foo.example/report”
</IfModule>

Tool to verify http response headers

To verify your http response headers fixes, you can test your url using on of the following tools/methods:

  • Security Headers
  • Redbot.org
  • or you can install a free wordpress plugin called “http headers plugin“

Happy Fixing!

Join Our Community

Previous Post

What is Web Light Search Results?

Next Post

Sidekick browser makes work apps more comfortable to access

Ahmed Maher

Ahmed Maher

Ahmed Maher is a marketing and growth leader with a proven track record across telecom, fintech, publishing, charity, government, e-commerce, and sports. He launched Vodafone Egypt’s digital and social media presence in 2008, setting new standards for brand engagement and performance marketing in the region. As the founder of Digital Boom, Ahmed has helped shape the voice of digital media in the Arab world. He brings a rare blend of creative vision and data-driven thinking, using digital tools and storytelling to drive measurable impact and scalable growth.

Related Stories

How to recover your hacked Facebook account?
Guides

How to Recover a Hacked Facebook Account

June 18, 2025 - Updated on June 20, 2025
How to Copy and paste between devices from your Mac/iPhone
Guides

How to Enable Copy and Paste Between Apple Devices

June 9, 2025
How to Become LLM-Ready in 2025: A Guide for Publishers
Guides

Publishing for Machines: The 2025 Guide to LLM-Ready Content

May 26, 2025
How to include current URL in a Webflow form?
Guides

Include current CMS item URL in Webflow forms

November 14, 2023 - Updated on May 16, 2025
How Positive Thinking Can Turbo Charge Your Career
Guides

How Positive Thinking Can Turbo Charge Your Career

July 5, 2023
How to increase the time limit to unsend emails on iPhone?
Guides

How to increase the delay time to unsend emails on iPhone?

September 19, 2022
5 Digital Marketing Strategies That Actually Matter in 2025

Top 5 Digital Marketing Strategies Winning MENA in 2025

June 21, 2025
The Labubu Effect: How a Toothy Toy Sparked a Global Obsession

The Labubu Effect: How a Toothy Toy Sparked a Global Obsession

June 20, 2025
How to recover your hacked Facebook account?

How to Recover a Hacked Facebook Account

June 18, 2025 - Updated on June 20, 2025
Best Restaurants and Steak Houses in Amman

10 Best Restaurants and Steakhouses in Amman

June 18, 2025
Winter in Jordan: 10 Best Places to Visit

10 Best Places to Visit in Jordan During Winter

June 18, 2025
Germany Begins Government-Wide Exit from Microsoft Software

Germany Begins Government-Wide Exit from Microsoft Software

June 14, 2025
  • Partners
  • Privacy Policy
  • About Us
  • Contact Us
  • Submit an Article

© 2025 Digital Boom, Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • News
  • Startups
  • Marketing
    • Digital Advertising
    • Insights
  • Campaigns
  • Tech
  • Guides
  • Market Watch
  • More
    • Careers
    • Ramadan Specials
    • Culture
    • Travel
    • Glossary

© 2025 Digital Boom, Inc.