WPIntell

Source evidence

Excellent

Security Headers · review · 2017-06-19T22:12:00+00:00

praisesentiment
highseverity
0.77relevance
2replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

5 / 16 rows with source links

31.2% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

11 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

review · 5 stars
bozon unresolved
Works really well! Tested with [link removed] For the future releases it would be good to include Content-Security-Policy and the forthcoming Expect-CT options. This topic was modified 8 years, 11 months ago by bdbrown . Reason: Links not permitted in reviews Thanks for the feedback. There are a couple of newer security headers I will look to support. I have abandoned any reasonable expectation of supporting Content-Security-Policy in WordPress sensibly. The problem with CSP is you want to provide it in the admin interface, as that is where the XSS issues that matter most, and it varies with each plugin used. That’s great! Looking forwards to that. With regards to SCP, would it be possible to have it in a form of an ‘advanced’ field, perhaps? For now, I am utilising .htaccess to add this header, but it would certainly be easier to have everything in one place. Although, I agree that SCP is a tricky subject, and requires from the admin some extra care. Cheers

Comments

2 shown
SimonRWaters 2017-06-20T10:01:00+00:00

Thanks for the feedback. There are a couple of newer security headers I will look to support. I have abandoned any reasonable expectation of supporting Content-Security-Policy in WordPress sensibly. The problem with CSP is you want to provide it in the admin interface, as that is where the XSS issues that matter most, and it varies with each plugin used.

bozon 2017-06-20T12:39:00+00:00

That’s great! Looking forwards to that. With regards to SCP, would it be possible to have it in a form of an ‘advanced’ field, perhaps? For now, I am utilising .htaccess to add this header, but it would certainly be easier to have everything in one place. Although, I agree that SCP is a tricky subject, and requires from the admin some extra care. Cheers