
BoundaryGuard Headers enforces modern HTTP security headers to harden your WordPress site against XSS, clickjacking, mixed content, and cross-origin attacks.
Key Features:
X-Powered-By and Server..htaccess Editing Required: Works without modifying server configuration files.Designed for developers and site owners who want stronger security without unnecessary complexity.
This plugin provides a Content Security Policy (CSP) builder. To assist users, it includes “Preset Buttons” that allow users to quickly add domain names to their own CSP whitelist.
This plugin DOES NOT connect to, load data from, or send data to these services automatically. The following third-party domains are referenced as presets within the admin dashboard for whitelisting purposes:
* Google Analytics (www.google-analytics.com) – Used for tracking whitelisting. [Privacy: https://policies.google.com/privacy]
* Google Tag Manager (www.googletagmanager.com) – Used for tag management. [Privacy: https://policies.google.com/privacy]
* Stripe (js.stripe.com, api.stripe.com) – Used for payment processing. [Privacy: https://stripe.com/privacy]
* Facebook (www.facebook.com, connect.facebook.net) – Used for social embeds. [Privacy: https://www.facebook.com/policy.php]
* YouTube (www.youtube.com, i.ytimg.com) – Used for video embeds. [Privacy: https://policies.google.com/privacy]
* Vimeo (player.vimeo.com) – Used for video embeds. [Privacy: https://vimeo.com/privacy]
* Gravatar (secure.gravatar.com) – Used for user avatars. [Privacy: https://automattic.com/privacy/]