{"id":339576,"date":"2026-07-20T16:54:18","date_gmt":"2026-07-20T16:54:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/zen-https-ssl\/"},"modified":"2026-07-20T16:54:04","modified_gmt":"2026-07-20T16:54:04","slug":"zen-site-security","status":"publish","type":"plugin","link":"https:\/\/ory.wordpress.org\/plugins\/zen-site-security\/","author":23513961,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.13.1","stable_tag":"1.13.1","tested":"7.0.2","requires":"6.5","requires_php":"8.0","requires_plugins":null,"header_name":"Zen Site Security","header_author":"Guram Zhgamadze","header_description":"Activate SSL in one click \u2014 HTTPS migration, 301 redirect, mixed content fixer, certificate monitoring, HSTS, security headers, and attack-surface hardening.","assets_banners_color":"f4f8fc","last_updated":"2026-07-20 16:54:04","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/github.com\/guramzhgamadze\/zen-site-security","header_author_uri":"https:\/\/profiles.wordpress.org\/guramzhgamadze\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":43,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.13.1":{"tag":"1.13.1","author":"guramzhgamadze","date":"2026-07-20 16:54:04"}},"upgrade_notice":{"1.13.1":"<p>Fixes Strict CSP (Report-Only) silently removing your enforcing CSP header. Recommended if you use the CSP features.<\/p>","1.13.0":"<p>The plugin has been renamed to Zen Site Security (new slug: zen-site-security).<\/p>","1.12.1":"<p>Corrects the plugin version shown on the settings page.<\/p>","1.12.0":"<p>Adds an optional security.txt (RFC 9116) responsible-disclosure file served at \/.well-known\/security.txt.<\/p>","1.11.0":"<p>The Dashboard widget now shows the TLS quality findings under the grade.<\/p>","1.10.0":"<p>Adds a CSP report \u2192 allowlist workflow (one-click &quot;Allow&quot; for blocked sources) and shows the TLS grade on the Dashboard widget.<\/p>","1.9.0":"<p>Adds a certificate quality (TLS) grade with specific findings and an SSL Labs deep-test link.<\/p>","1.8.0":"<p>Adds a Dashboard security-score widget with one-click recommended setup, and Site Health integration.<\/p>","1.7.0":"<p>Adds certificate-expiry email alerts via a daily background check, so an expiring certificate is caught even if nobody visits wp-admin.<\/p>","1.6.0":"<p>Adds opt-in Strict CSP with script nonces (report-only by default) and fixes an .htaccess CSP that could emit upgrade-insecure-requests before SSL was active.<\/p>","1.5.0":"<p>Optional server-level security headers (.htaccess) so static files are covered too \u2014 addresses scanners that flag missing headers on assets.<\/p>","1.4.0":"<p>Settings moved to a top-level &quot;Zen Site Security&quot; menu with a refreshed admin design; translation template added.<\/p>","1.3.0":"<p>Adds web cache deception protection (no-store on private responses) and opt-in CSP anti-XSS directives. Recommended if a CDN or page cache sits in front of your site.<\/p>","1.2.0":"<p>Adds sensitive-file blocking, directory-listing hardening, X-Powered-By removal, and clean pairing with Zen Login &amp; Authentication (one owner per control).<\/p>","1.1.0":"<p>Fixes SSL activation not persisting, and adds the opt-in security hardening module (security headers, SameSite cookies, attack-surface reduction). Recommended for all users.<\/p>","1.0.0":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3615568,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3615568,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3615568,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3615568,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.13.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3615568,"resolution":"1","location":"assets","locale":"","width":1431,"height":714},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3615568,"resolution":"2","location":"assets","locale":"","width":1434,"height":481},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3615568,"resolution":"3","location":"assets","locale":"","width":1436,"height":662},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3615568,"resolution":"4","location":"assets","locale":"","width":1446,"height":878},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3615568,"resolution":"5","location":"assets","locale":"","width":1443,"height":878},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3615568,"resolution":"6","location":"assets","locale":"","width":1419,"height":772},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3615568,"resolution":"7","location":"assets","locale":"","width":1424,"height":624},"screenshot-8.png":{"filename":"screenshot-8.png","revision":3615568,"resolution":"8","location":"assets","locale":"","width":1419,"height":241},"screenshot-9.png":{"filename":"screenshot-9.png","revision":3615568,"resolution":"9","location":"assets","locale":"","width":451,"height":372}},"screenshots":{"1":"One-click SSL activation: certificate status, active-SSL and redirect cards, and a live TLS quality grade (A) that inspects your protocol, key, signature and chain.","2":"Choose how HTTP is sent to HTTPS \u2014 PHP 301 (works everywhere) or .htaccess \u2014 plus the mixed content fixer for the front end and, optionally, wp-admin.","3":"HTTP Strict Transport Security (HSTS) with safe max-age tiers and preload safeguards, and a daily background check that emails you before your certificate expires.","4":"Security headers \u2014 X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy and CSP \u2014 with optional server-level (.htaccess) delivery so static files are covered too. Sibling-aware when Zen Login &amp; Authentication is active.","5":"Strict CSP with per-request script nonces \u2014 Report-Only by default, with a violations panel and one-click allowlisting of the sources you recognise.","6":"Attack-surface hardening: web cache deception protection, SameSite login cookies, disabled file editors, blocked PHP execution in uploads, sensitive-file and directory-listing rules, and version hiding.","7":"Optional security.txt (RFC 9116), served on the fly at \/.well-known\/security.txt with your security contact, policy URL and preferred languages.","8":"Built-in emergency recovery \u2014 a single wp-config.php constant reverts everything if a certificate problem ever locks you out.","9":"At-a-glance security score on the WordPress Dashboard, with the TLS grade and a one-click \"enable recommended protections\" button."}},"plugin_section":[262246],"plugin_tags":[31093,34310,1908,153786,1536],"plugin_category":[54],"plugin_contributors":[271108],"plugin_business_model":[],"class_list":["post-339576","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-hardening","plugin_tags-hsts","plugin_tags-https","plugin_tags-security-headers","plugin_tags-ssl","plugin_category-security-and-spam-protection","plugin_contributors-guramzhgamadze","plugin_committers-guramzhgamadze"],"banners":{"banner":"https:\/\/ps.w.org\/zen-site-security\/assets\/banner-772x250.png?rev=3615568","banner_2x":"https:\/\/ps.w.org\/zen-site-security\/assets\/banner-1544x500.png?rev=3615568","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/zen-site-security\/assets\/icon-128x128.png?rev=3615568","icon_2x":"https:\/\/ps.w.org\/zen-site-security\/assets\/icon-256x256.png?rev=3615568","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/zen-site-security\/assets\/screenshot-1.png?rev=3615568","caption":"One-click SSL activation: certificate status, active-SSL and redirect cards, and a live TLS quality grade (A) that inspects your protocol, key, signature and chain."},{"src":"https:\/\/ps.w.org\/zen-site-security\/assets\/screenshot-2.png?rev=3615568","caption":"Choose how HTTP is sent to HTTPS \u2014 PHP 301 (works everywhere) or .htaccess \u2014 plus the mixed content fixer for the front end and, optionally, wp-admin."},{"src":"https:\/\/ps.w.org\/zen-site-security\/assets\/screenshot-3.png?rev=3615568","caption":"HTTP Strict Transport Security (HSTS) with safe max-age tiers and preload safeguards, and a daily background check that emails you before your certificate expires."},{"src":"https:\/\/ps.w.org\/zen-site-security\/assets\/screenshot-4.png?rev=3615568","caption":"Security headers \u2014 X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy and CSP \u2014 with optional server-level (.htaccess) delivery so static files are covered too. Sibling-aware when Zen Login &amp; Authentication is active."},{"src":"https:\/\/ps.w.org\/zen-site-security\/assets\/screenshot-5.png?rev=3615568","caption":"Strict CSP with per-request script nonces \u2014 Report-Only by default, with a violations panel and one-click allowlisting of the sources you recognise."},{"src":"https:\/\/ps.w.org\/zen-site-security\/assets\/screenshot-6.png?rev=3615568","caption":"Attack-surface hardening: web cache deception protection, SameSite login cookies, disabled file editors, blocked PHP execution in uploads, sensitive-file and directory-listing rules, and version hiding."},{"src":"https:\/\/ps.w.org\/zen-site-security\/assets\/screenshot-7.png?rev=3615568","caption":"Optional security.txt (RFC 9116), served on the fly at \/.well-known\/security.txt with your security contact, policy URL and preferred languages."},{"src":"https:\/\/ps.w.org\/zen-site-security\/assets\/screenshot-8.png?rev=3615568","caption":"Built-in emergency recovery \u2014 a single wp-config.php constant reverts everything if a certificate problem ever locks you out."},{"src":"https:\/\/ps.w.org\/zen-site-security\/assets\/screenshot-9.png?rev=3615568","caption":"At-a-glance security score on the WordPress Dashboard, with the TLS grade and a one-click \"enable recommended protections\" button."}],"raw_content":"<!--section=description-->\n<p>Zen Site Security migrates your WordPress site to HTTPS safely and keeps it there.<\/p>\n\n<p><strong>One-click activation<\/strong><\/p>\n\n<p>The plugin first verifies that a valid SSL certificate is actually installed for your domain \u2014 activation is blocked until one is found, so you can never lock yourself out by accident. Activation then:<\/p>\n\n<ul>\n<li>switches your WordPress Address and Site Address to https,<\/li>\n<li>301-redirects every HTTP request (pages, REST API) to HTTPS,<\/li>\n<li>fixes mixed content on your pages on the fly.<\/li>\n<\/ul>\n\n<p><strong>HTTP to HTTPS redirect, your way<\/strong><\/p>\n\n<ul>\n<li><strong>PHP 301 redirect<\/strong> (default) \u2014 works on every server and disappears automatically when the plugin is deactivated.<\/li>\n<li><strong>.htaccess 301 redirect<\/strong> (advanced, Apache\/LiteSpeed) \u2014 redirects at server level before WordPress loads, with the PHP redirect kept as a safety net. The rules are placed above the WordPress block, wrapped in clear markers, and removed on deactivation.<\/li>\n<li>On nginx the plugin shows you the exact server snippet to copy instead.<\/li>\n<\/ul>\n\n<p><strong>Mixed content fixer<\/strong><\/p>\n\n<p>Insecure <code>http:\/\/<\/code> references to your own site (including www\/non-www variants and JSON-escaped URLs), plus common <code>src<\/code>, <code>href<\/code>, <code>action<\/code>, <code>og:image<\/code>, <code>url()<\/code> and <code>srcset<\/code> patterns, are rewritten to <code>https:\/\/<\/code> just before the page is sent to the browser. Feeds, sitemaps and JSON responses are left untouched. An optional fixer for the WordPress admin is available too.<\/p>\n\n<p><strong>Certificate monitoring<\/strong><\/p>\n\n<p>The dashboard shows the certificate issuer, expiry date, and whether it covers your domain (wildcards included). When SSL is active and the certificate is about to expire (or already has), administrators see a warning.<\/p>\n\n<p><strong>HTTP Strict Transport Security (HSTS) \u2014 opt-in<\/strong><\/p>\n\n<p>Once your site runs reliably on https, you can send the <code>Strict-Transport-Security<\/code> header. Max-age starts at one day for safe testing; the preload-eligible configuration (1 year + includeSubDomains) requires explicit opt-in, because it is hard to undo.<\/p>\n\n<p><strong>Security hardening \u2014 XSS, CSRF, and injection defense in depth (all opt-in)<\/strong><\/p>\n\n<ul>\n<li><strong>Security headers<\/strong>: <code>X-Content-Type-Options: nosniff<\/code>, <code>X-Frame-Options<\/code> (clickjacking), <code>Referrer-Policy<\/code> (keeps tokens out of cross-site referrers), a conservative <code>Permissions-Policy<\/code>, and CSP <code>upgrade-insecure-requests<\/code>. Every header stands down automatically if another plugin already sends it.<\/li>\n<li><strong>SameSite login cookies<\/strong>: the WordPress auth cookies are re-issued with an explicit <code>SameSite=Lax<\/code> attribute, so CSRF protection no longer depends on browser defaults \u2014 a second layer next to WordPress nonces.<\/li>\n<li><strong>Attack-surface reduction<\/strong>: disable the wp-admin file editors (<code>DISALLOW_FILE_EDIT<\/code>), block PHP execution in the uploads directory (an uploaded webshell becomes a dead file), deny web access to sensitive files (logs, database dumps, backup copies, wp-config variants), disable directory listings, disable XML-RPC and pingbacks, and hide the WordPress version and PHP <code>X-Powered-By<\/code> header.<\/li>\n<\/ul>\n\n<p><strong>Built to pair with Zen Login &amp; Authentication<\/strong><\/p>\n\n<p>The two Zen plugins split the work cleanly: Zen Login &amp; Authentication owns identity security (login forms, brute-force protection, 2FA, passkeys, user enumeration, XML-RPC), while this plugin owns transport and platform security (HTTPS, headers, cookies, file-system attack surface). When both are active, each control has exactly one owner \u2014 for example, this plugin's XML-RPC switch automatically defers to its sibling. Each plugin is fully standalone; neither requires the other.<\/p>\n\n<p><strong>Web cache deception protection<\/strong><\/p>\n\n<p>When a CDN or page cache sits in front of your site, an attacker can try to trick it into storing a victim's private page under a URL they control (for example by appending a fake <code>.css<\/code> to an account page). This plugin marks logged-in pages and authenticated REST responses as <code>Cache-Control: no-store, private<\/code>, and refuses to let a dynamic response be cached under a static-looking URL \u2014 the origin-side defense recommended by OWASP and PortSwigger.<\/p>\n\n<p>Honest scope: these features reduce attack surface and blunt common exploit paths. They are defense in depth \u2014 they cannot fix an injection, XSS or XXE vulnerability inside another plugin's or theme's code, and no plugin can. Server-side injection (SQL\/NoSQL), XML external entity (XXE) and web LLM\/prompt-injection flaws are fixed in the application code that has the bug; keep WordPress, plugins and themes updated, and use security headers here as a second layer.<\/p>\n\n<p><strong>Locked out? Built-in emergency recovery<\/strong><\/p>\n\n<p>If anything goes wrong, add one line to wp-config.php:<\/p>\n\n<pre><code>define( 'ZENSS_DISABLE_SSL', true );\n<\/code><\/pre>\n\n<p>On the next visit the plugin reverts your site to http, disables the redirect, and removes its .htaccess rules.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install and activate the plugin.<\/li>\n<li>Go to <strong>Settings \u2192 HTTPS &amp; SSL<\/strong>.<\/li>\n<li>If a valid certificate is detected, click <strong>Activate SSL &amp; HTTPS redirect<\/strong>.<\/li>\n<li>Done \u2014 optionally enable HSTS later, once everything runs smoothly.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20the%20plugin%20generate%20ssl%20certificates%3F\"><h3>Does the plugin generate SSL certificates?<\/h3><\/dt>\n<dd><p>No. Your hosting provider installs the certificate (most offer free Let's Encrypt certificates in their control panel). This plugin detects the certificate, migrates WordPress to https, and keeps the site redirected and mixed-content free.<\/p><\/dd>\n<dt id=\"what%20happens%20when%20i%20deactivate%20the%20plugin%3F\"><h3>What happens when I deactivate the plugin?<\/h3><\/dt>\n<dd><p>The plugin removes its .htaccess rules, and the PHP redirect stops. Your site URLs stay on https on purpose \u2014 deactivating a plugin should never push a working https site back to http. Use \"Revert site to HTTP\" on the settings page first if you really want to go back.<\/p><\/dd>\n<dt id=\"i%20activated%20ssl%20and%20now%20i%20cannot%20reach%20my%20site.%20what%20do%20i%20do%3F\"><h3>I activated SSL and now I cannot reach my site. What do I do?<\/h3><\/dt>\n<dd><p>Add <code>define( 'ZENSS_DISABLE_SSL', true );<\/code> to wp-config.php via FTP or your hosting file manager. The plugin reverts everything on the next request. Remove the line once your certificate is fixed.<\/p><\/dd>\n<dt id=\"does%20it%20work%20behind%20a%20proxy%20or%20load%20balancer%3F\"><h3>Does it work behind a proxy or load balancer?<\/h3><\/dt>\n<dd><p>Yes. The .htaccess rules skip requests that already arrive with <code>X-Forwarded-Proto: https<\/code>, preventing redirect loops. If your proxy terminates SSL and WordPress does not detect it, your proxy setup needs the standard <code>HTTP_X_FORWARDED_PROTO<\/code> handling in wp-config.php.<\/p><\/dd>\n<dt id=\"can%20this%20plugin%20stop%20sql%20injection%20or%20xss%20vulnerabilities%20in%20my%20other%20plugins%3F\"><h3>Can this plugin stop SQL injection or XSS vulnerabilities in my other plugins?<\/h3><\/dt>\n<dd><p>No plugin can patch vulnerable code in another plugin \u2014 be wary of any that claims to. What this plugin does is defense in depth: security headers that make XSS harder to exploit, SameSite cookies that blunt CSRF, and attack-surface reduction (no file editors, no PHP execution in uploads, no XML-RPC) that turns many injection exploit paths into dead ends. Keeping WordPress, plugins and themes updated remains essential.<\/p><\/dd>\n<dt id=\"is%20multisite%20supported%3F\"><h3>Is multisite supported?<\/h3><\/dt>\n<dd><p>Version 1.x targets single-site installs. Multisite support is planned.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20work%20together%20with%20zen%20login%20%26%20authentication%3F\"><h3>Does this plugin work together with Zen Login &amp; Authentication?<\/h3><\/dt>\n<dd><p>Yes \u2014 they are designed as a pair that fills each other's gaps. Zen Login &amp; Authentication covers identity and login security; this plugin covers transport and platform security. When both are active, overlapping controls (like XML-RPC) are owned by exactly one of them, and site-wide security headers automatically stand down on pages where the sibling already sends them. Each plugin also works fine on its own.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.13.1<\/h4>\n\n<ul>\n<li>Fix: enabling Strict CSP in Report-Only mode no longer removes the enforcing Content-Security-Policy from your front end, and no longer drops CSP from wp-admin. The enforcing baseline policy now stays in place until Strict CSP is actually switched to Enforce, alongside the Report-Only strict policy.<\/li>\n<\/ul>\n\n<h4>1.13.0<\/h4>\n\n<ul>\n<li>Renamed from \"Zen HTTPS &amp; SSL\" to \"Zen Site Security\" (new slug: zen-site-security). The plugin now covers far more than SSL \u2014 security headers, hardening, Content-Security-Policy, certificate monitoring and security.txt \u2014 so the broader name reflects what it actually does.<\/li>\n<\/ul>\n\n<h4>1.12.1<\/h4>\n\n<ul>\n<li>Fix: the version number shown on the settings page lagged behind the actual plugin version (the internal version constant was not bumped in 1.12.0).<\/li>\n<\/ul>\n\n<h4>1.12.0<\/h4>\n\n<ul>\n<li>New: optional security.txt (RFC 9116) \u2014 a responsible-disclosure file served on the fly at \/.well-known\/security.txt (and \/security.txt), with configurable Contact, Policy URL and Preferred-Languages. No file is written to disk, so it never clashes with Let's Encrypt \/ ACME challenges.<\/li>\n<\/ul>\n\n<h4>1.11.0<\/h4>\n\n<ul>\n<li>Improved: the Dashboard security widget now lists the certificate quality findings (protocol, key, signature) beneath the TLS grade, matching the settings page.<\/li>\n<\/ul>\n\n<h4>1.10.0<\/h4>\n\n<ul>\n<li>New: CSP report \u2192 allowlist workflow. The strict CSP now also governs styles, images, fonts, connections, frames and media, so the violations panel shows exactly what would be blocked \u2014 and each recognised source gets a one-click \"Allow\" button that adds it to the policy. A \"ready to enforce?\" nudge appears once report-only has been quiet for two weeks. Scripts remain governed by the nonce (they can't be host-allowlisted, and the panel says so).<\/li>\n<li>New: the Dashboard security widget now shows the certificate quality (TLS) grade too, alongside the security score.<\/li>\n<\/ul>\n\n<h4>1.9.0<\/h4>\n\n<ul>\n<li>New: Certificate quality (TLS) grading \u2014 a letter grade with specific findings for the negotiated protocol, key strength, signature algorithm, cipher and certificate chain, shown on the settings page. Honest about scope (it inspects your certificate and the negotiated connection) and links to the SSL Labs deep test for a full protocol\/cipher audit.<\/li>\n<\/ul>\n\n<h4>1.8.0<\/h4>\n\n<ul>\n<li>New: Dashboard security-score widget \u2014 an at-a-glance score (0\u2013100), how many protections are active, your top recommended next steps, and a one-click \"Enable recommended protections\" button that turns on the safe defaults for you.<\/li>\n<li>New: Site Health integration \u2014 the plugin's protections now appear as tests under Tools \u2192 Site Health (HTTPS\/SSL, security headers, hardening), plus a full posture breakdown in the Info tab.<\/li>\n<li>Both surfaces are driven by one shared posture engine, so the score, the recommendations, and the Site Health tests always agree.<\/li>\n<\/ul>\n\n<h4>1.7.0<\/h4>\n\n<ul>\n<li>New: certificate expiry email alerts \u2014 a daily background check (WP-Cron) re-probes your SSL certificate independently of admin visits and emails the site administrator once when fewer than 15 days remain, and once more if it expires. Opt-out toggle under Notifications; requires SSL to be active.<\/li>\n<\/ul>\n\n<h4>1.6.0<\/h4>\n\n<ul>\n<li>New: Strict CSP (script nonces) \u2014 an advanced, opt-in Content-Security-Policy that stamps a per-request nonce on WordPress-rendered scripts and ships <code>script-src 'nonce-\u2026' 'strict-dynamic'<\/code>. Report-Only by default with a violations panel; a separate front-end-only \"Enforce\" toggle.<\/li>\n<li>Fix: the .htaccess CSP no longer emits upgrade-insecure-requests when SSL is not active \u2014 it now tracks the real SSL state instead of assuming https.<\/li>\n<\/ul>\n\n<h4>1.5.0<\/h4>\n\n<ul>\n<li>New: \"Server-level headers\" option \u2014 write the security headers into .htaccess (mod_headers) so static files (CSS, JS, images, fonts) and non-WordPress responses are covered, not just pages WordPress renders. Uses <code>Header always set<\/code>, so PHP-rendered pages are never double-headed; removed cleanly on deactivation.<\/li>\n<li>The server-level HSTS line is guarded by an https expression and stays in sync with SSL activation\/reversion.<\/li>\n<\/ul>\n\n<h4>1.4.0<\/h4>\n\n<ul>\n<li>New: translation template (languages\/zen-site-security.pot) \u2014 the plugin is fully translation-ready.<\/li>\n<li>Improved: the settings page moved from Settings \u2192 HTTPS &amp; SSL to its own top-level \"Zen Site Security\" menu entry, next to Zen Login &amp; Authentication.<\/li>\n<li>Improved: the settings page now uses the Zen family admin theme \u2014 card layout, toggle switches, and clearer grouping.<\/li>\n<\/ul>\n\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>New: Web cache deception protection \u2014 Cache-Control: no-store, private on authenticated pages and REST responses, and on dynamic responses served under static-looking URLs; signals common page-cache plugins to bypass logged-in responses.<\/li>\n<li>New: opt-in CSP anti-XSS directives \u2014 object-src 'none', base-uri 'self', and frame-ancestors mirroring your clickjacking setting, assembled into a single Content-Security-Policy header.<\/li>\n<li>Docs: honest scope statement on injection\/XXE\/LLM classes \u2014 defense in depth, not a patch for vulnerable third-party code.<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>New: sibling awareness \u2014 when Zen Login &amp; Authentication is active, the XML-RPC switch defers to it (single owner per control) and the settings page shows the division of responsibilities.<\/li>\n<li>New: deny web access to sensitive files \u2014 logs, SQL dumps, backup\/editor copies, wp-config variants, readme.html, license.txt (managed .htaccess block).<\/li>\n<li>New: disable directory listings (Options -Indexes, with a documented recovery path).<\/li>\n<li>Improved: the version-disclosure toggle now also removes PHP's X-Powered-By header.<\/li>\n<li>Fix: managed .htaccess block markers are line-anchored so the redirect and hardening blocks can never swallow each other.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>New: Security hardening module (all opt-in).<\/li>\n<li>New: Security headers \u2014 X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, CSP upgrade-insecure-requests \u2014 with automatic stand-down when another plugin already sends the header.<\/li>\n<li>New: SameSite=Lax re-issue of the WordPress auth cookies (CSRF defense in depth).<\/li>\n<li>New: Disable wp-admin file editors, block PHP execution in uploads, disable XML-RPC\/pingbacks, hide the WordPress version.<\/li>\n<li>Fix: SSL activation could not persist \u2014 the registered-settings sanitizer reverted the ssl_enabled flag on every activation click. The flag now lives outside the registered settings array.<\/li>\n<li>Fix: SSL status card no longer claims \"site runs on http\" when the site URLs already use https.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<li>One-click SSL activation with certificate verification.<\/li>\n<li>PHP 301 redirect (default) and optional .htaccess redirect with automatic cleanup.<\/li>\n<li>Front-end (and opt-in admin) mixed content fixer.<\/li>\n<li>Certificate dashboard with expiry warnings.<\/li>\n<li>Opt-in HSTS with preload safeguards.<\/li>\n<li>Emergency recovery via the ZENSS_DISABLE_SSL constant.<\/li>\n<\/ul>","raw_excerpt":"SSL in one click plus security hardening: 301 HTTPS redirect, mixed content fixer, HSTS, security headers, SameSite cookies, attack-surface hardening.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ory.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/339576","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ory.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/ory.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/ory.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=339576"}],"author":[{"embeddable":true,"href":"https:\/\/ory.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/guramzhgamadze"}],"wp:attachment":[{"href":"https:\/\/ory.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=339576"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/ory.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=339576"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/ory.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=339576"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/ory.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=339576"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/ory.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=339576"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/ory.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=339576"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}