[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fOq_-FwrL6T2S5-sXPFLpNsKAZYqtsBVorlewxIsQzuE":3,"$fbx-UanVeskZiNT0PR9mlICWJ0nKA10NsbSbCwsECARc":132,"$fiNRgsWri4hrObaP92YiUGRv3ha2YctKIfLaxU3Y3Nyg":137},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":23,"download_link":24,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":36,"analysis":26,"fingerprints":26},"zen-site-security","Zen Site Security","1.13.1","Guram Zhgamadze","https:\u002F\u002Fprofiles.wordpress.org\u002Fguramzhgamadze\u002F","\u003Cp>Zen Site Security migrates your WordPress site to HTTPS safely and keeps it there.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>One-click activation\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The plugin first verifies that a valid SSL certificate is actually installed for your domain — activation is blocked until one is found, so you can never lock yourself out by accident. Activation then:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>switches your WordPress Address and Site Address to https,\u003C\u002Fli>\n\u003Cli>301-redirects every HTTP request (pages, REST API) to HTTPS,\u003C\u002Fli>\n\u003Cli>fixes mixed content on your pages on the fly.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>HTTP to HTTPS redirect, your way\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>PHP 301 redirect\u003C\u002Fstrong> (default) — works on every server and disappears automatically when the plugin is deactivated.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>.htaccess 301 redirect\u003C\u002Fstrong> (advanced, Apache\u002FLiteSpeed) — redirects at server level before WordPress loads, with the PHP redirect kept as a safety net. The rules are placed above the WordPress block, wrapped in clear markers, and removed on deactivation.\u003C\u002Fli>\n\u003Cli>On nginx the plugin shows you the exact server snippet to copy instead.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Mixed content fixer\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Insecure \u003Ccode>http:\u002F\u002F\u003C\u002Fcode> references to your own site (including www\u002Fnon-www variants and JSON-escaped URLs), plus common \u003Ccode>src\u003C\u002Fcode>, \u003Ccode>href\u003C\u002Fcode>, \u003Ccode>action\u003C\u002Fcode>, \u003Ccode>og:image\u003C\u002Fcode>, \u003Ccode>url()\u003C\u002Fcode> and \u003Ccode>srcset\u003C\u002Fcode> patterns, are rewritten to \u003Ccode>https:\u002F\u002F\u003C\u002Fcode> just before the page is sent to the browser. Feeds, sitemaps and JSON responses are left untouched. An optional fixer for the WordPress admin is available too.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Certificate monitoring\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The dashboard shows the certificate issuer, expiry date, and whether it covers your domain (wildcards included). When SSL is active and the certificate is about to expire (or already has), administrators see a warning.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>HTTP Strict Transport Security (HSTS) — opt-in\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Once your site runs reliably on https, you can send the \u003Ccode>Strict-Transport-Security\u003C\u002Fcode> header. Max-age starts at one day for safe testing; the preload-eligible configuration (1 year + includeSubDomains) requires explicit opt-in, because it is hard to undo.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security hardening — XSS, CSRF, and injection defense in depth (all opt-in)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Security headers\u003C\u002Fstrong>: \u003Ccode>X-Content-Type-Options: nosniff\u003C\u002Fcode>, \u003Ccode>X-Frame-Options\u003C\u002Fcode> (clickjacking), \u003Ccode>Referrer-Policy\u003C\u002Fcode> (keeps tokens out of cross-site referrers), a conservative \u003Ccode>Permissions-Policy\u003C\u002Fcode>, and CSP \u003Ccode>upgrade-insecure-requests\u003C\u002Fcode>. Every header stands down automatically if another plugin already sends it.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SameSite login cookies\u003C\u002Fstrong>: the WordPress auth cookies are re-issued with an explicit \u003Ccode>SameSite=Lax\u003C\u002Fcode> attribute, so CSRF protection no longer depends on browser defaults — a second layer next to WordPress nonces.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Attack-surface reduction\u003C\u002Fstrong>: disable the wp-admin file editors (\u003Ccode>DISALLOW_FILE_EDIT\u003C\u002Fcode>), block PHP execution in the uploads directory (an uploaded webshell becomes a dead file), deny web access to sensitive files (logs, database dumps, backup copies, wp-config variants), disable directory listings, disable XML-RPC and pingbacks, and hide the WordPress version and PHP \u003Ccode>X-Powered-By\u003C\u002Fcode> header.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Built to pair with Zen Login & Authentication\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The two Zen plugins split the work cleanly: Zen Login & Authentication owns identity security (login forms, brute-force protection, 2FA, passkeys, user enumeration, XML-RPC), while this plugin owns transport and platform security (HTTPS, headers, cookies, file-system attack surface). When both are active, each control has exactly one owner — for example, this plugin’s XML-RPC switch automatically defers to its sibling. Each plugin is fully standalone; neither requires the other.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Web cache deception protection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>When a CDN or page cache sits in front of your site, an attacker can try to trick it into storing a victim’s private page under a URL they control (for example by appending a fake \u003Ccode>.css\u003C\u002Fcode> to an account page). This plugin marks logged-in pages and authenticated REST responses as \u003Ccode>Cache-Control: no-store, private\u003C\u002Fcode>, and refuses to let a dynamic response be cached under a static-looking URL — the origin-side defense recommended by OWASP and PortSwigger.\u003C\u002Fp>\n\u003Cp>Honest scope: these features reduce attack surface and blunt common exploit paths. They are defense in depth — they cannot fix an injection, XSS or XXE vulnerability inside another plugin’s or theme’s code, and no plugin can. Server-side injection (SQL\u002FNoSQL), XML external entity (XXE) and web LLM\u002Fprompt-injection flaws are fixed in the application code that has the bug; keep WordPress, plugins and themes updated, and use security headers here as a second layer.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Locked out? Built-in emergency recovery\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>If anything goes wrong, add one line to wp-config.php:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>define( 'ZENSS_DISABLE_SSL', true );\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>On the next visit the plugin reverts your site to http, disables the redirect, and removes its .htaccess rules.\u003C\u002Fp>\n","SSL in one click plus security hardening: 301 HTTPS redirect, mixed content fixer, HSTS, security headers, SameSite cookies, attack-surface hardening.",0,32,"2026-07-20T16:54:00.000Z","7.0.2","6.5","8.0",[18,19,20,21,22],"hardening","hsts","https","security-headers","ssl","https:\u002F\u002Fgithub.com\u002Fguramzhgamadze\u002Fzen-site-security","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fzen-site-security.1.13.1.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":31,"display_name":7,"profile_url":8,"plugin_count":32,"total_installs":11,"avg_security_score":25,"avg_patch_time_days":33,"trust_score":34,"computed_at":35},"guramzhgamadze",1,30,94,"2026-08-29T01:42:18.930Z",[37,59,76,95,113],{"slug":38,"name":39,"version":40,"author":41,"author_profile":42,"description":43,"short_description":44,"active_installs":45,"downloaded":46,"rating":47,"num_ratings":48,"last_updated":49,"tested_up_to":50,"requires_at_least":51,"requires_php":52,"tags":53,"homepage":56,"download_link":57,"security_score":58,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"lh-hsts","LH HSTS","1.25","shawfactor","https:\u002F\u002Fprofiles.wordpress.org\u002Fshawfactor\u002F","\u003Cp>This plugin send the proper headers for full ssl security. For more information on what this is and why it is important visit: http:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FHTTP_Strict_Transport_Security\u003C\u002Fp>\n\u003Cp>The options are preset to enable browsers to preload the HSTS directive but can be overwritten by filters which are clearly documented in the code.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Did you find this plugin helpful? Please consider \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fview\u002Fplugin-reviews\u002Flh-hsts\" rel=\"ugc\">writing a review\u003C\u002Fa>.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Ch3>To update the max-age settings, add the following code to your functions.php\u003C\u002Fh3>\n\u003Cpre>\u003Ccode>add_filter('lh_hsts_max_age', 'modify_ls_hsts_max_age_func');\n\nfunction modify_ls_hsts_max_age_func( $max_age ){\n    return false;\n}\n    `\n\n\u003Ch3>To update the subdomain settings, add the following code to your functions.php\u003C\u002Fh3>\n\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>add_filter(‘lh_hsts_subdomain’, ‘modify_ls_hsts_subdomain_func’);\u003C\u002Fp>\n\u003Cp>function modify_ls_hsts_subdomain_func( $subdomain ){\u003Cbr \u002F>\n    return false;\u003Cbr \u002F>\n}\u003Cbr \u002F>\n    `\u003C\u002Fp>\n\u003Ch3>To update the preload setting, add the following code to your functions.php\u003C\u002Fh3>\n\u003Cpre>\u003Ccode>add_filter('lh_hsts_preload', 'modify_ls_hsts_preload_func');\n\nfunction modify_ls_hsts_preload_func( $preload ){\n    return false;\n}\n    `\n\n\u003Ch3>To update the redirect setting, add the following code to your functions.php\u003C\u002Fh3>\n\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>add_filter(‘lh_hsts_redirect’, ‘modify_ls_hsts_redirect_func’);\u003C\u002Fp>\n\u003Cp>function modify_ls_hsts_redirect_func( $redirect ){\u003Cbr \u002F>\n    return false;\u003Cbr \u002F>\n}\u003Cbr \u002F>\n    `\u003C\u002Fp>\n","HSTS is HTTP Strict Transport Security, a means to enforce using SSL even if the user accesses the site through HTTP and not HTTPS.",600,356133,78,7,"2020-07-12T05:30:00.000Z","5.4.19","3.0","",[19,20,54,55,22],"redirect","security","https:\u002F\u002Flhero.org\u002Fportfolio\u002Flh-hsts\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flh-hsts.zip",85,{"slug":60,"name":61,"version":62,"author":63,"author_profile":64,"description":65,"short_description":66,"active_installs":67,"downloaded":68,"rating":25,"num_ratings":69,"last_updated":70,"tested_up_to":14,"requires_at_least":71,"requires_php":72,"tags":73,"homepage":52,"download_link":75,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"volixta-ssl-security-headers","Volixta SSL & Security Headers","1.1.5","VOLIXTA TEAM","https:\u002F\u002Fprofiles.wordpress.org\u002Fvolixta\u002F","\u003Cp>Is your WordPress site still serving pages over \u003Cstrong>HTTP\u003C\u002Fstrong> instead of \u003Cstrong>HTTPS\u003C\u002Fstrong>?\u003Cbr \u002F>\nDo you see browser warnings like \u003Cem>“Not Secure”\u003C\u002Fem> even though you installed SSL?\u003Cbr \u002F>\nAre you getting \u003Cstrong>mixed content errors\u003C\u002Fstrong> in Chrome or Firefox after enabling HTTPS?\u003Cbr \u002F>\nIs your Site Health report complaining about missing \u003Cstrong>security headers\u003C\u002Fstrong>?\u003C\u002Fp>\n\u003Cp>👉 \u003Cstrong>Volixta SSL & Security Headers fixes all of these in a few clicks.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Easily \u003Cstrong>activate SSL\u003C\u002Fstrong>, \u003Cstrong>force 301 redirects\u003C\u002Fstrong>, repair \u003Cstrong>mixed content\u003C\u002Fstrong>, and apply recommended \u003Cstrong>WordPress security headers\u003C\u002Fstrong> like HSTS, CSP, and X-Frame-Options.\u003C\u002Fp>\n\u003Ch3>🔐 What does Volixta do?\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Activate SSL automatically\u003C\u002Fstrong>: safely update your WordPress \u003Ccode>home\u003C\u002Fcode> and \u003Ccode>siteurl\u003C\u002Fcode> to use \u003Ccode>https:\u002F\u002F\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Force HTTPS with 301 redirect\u003C\u002Fstrong>: adds a safe \u003Ccode>.htaccess\u003C\u002Fcode> block on Apache\u002FLiteSpeed, or falls back to a PHP redirect if needed.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Fix mixed content\u003C\u002Fstrong>: scans your posts, postmeta, and options for \u003Ccode>http:\u002F\u002F\u003C\u002Fcode> links and replaces them with \u003Ccode>https:\u002F\u002F\u003C\u002Fcode> (serialization-safe).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Apply modern HTTP Security Headers\u003C\u002Fstrong>: HSTS, Content-Security-Policy (\u003Ccode>upgrade-insecure-requests\u003C\u002Fcode>), X-Frame-Options, Referrer-Policy, Permissions-Policy, COOP\u002FCOEP\u002FCORP.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Nginx friendly\u003C\u002Fstrong>: when \u003Ccode>.htaccess\u003C\u002Fcode> is not available, Volixta shows ready-to-copy Nginx rules.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Site Health integration\u003C\u002Fstrong>: checks for SSL, redirects, and security headers.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>✅ Why choose Volixta?\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>Safe by design\u003C\u002Fstrong>\u003Cbr \u002F>\nNothing is applied automatically. You choose what to enable. Each \u003Ccode>.htaccess\u003C\u002Fcode> modification creates a timestamped backup.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Serialization-safe mixed content fixer\u003C\u002Fstrong>\u003Cbr \u002F>\nNo risk of breaking complex serialized data in \u003Ccode>postmeta\u003C\u002Fcode> or \u003Ccode>options\u003C\u002Fcode>.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Admin-only processing\u003C\u002Fstrong>\u003Cbr \u002F>\nEverything runs in the admin area. The frontend only uses the optional PHP redirect when required.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Localhost aware\u003C\u002Fstrong>\u003Cbr \u002F>\nDetects local environments (\u003Ccode>localhost\u003C\u002Fcode>, \u003Ccode>.local\u003C\u002Fcode>, \u003Ccode>.test\u003C\u002Fcode>) and provides instructions for enabling trusted HTTPS locally with \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FFiloSottile\u002Fmkcert\" rel=\"nofollow ugc\">mkcert\u003C\u002Fa>.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🔎 Typical problems solved\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>How do I activate SSL in WordPress?\u003C\u002Fstrong>\u003Cbr \u002F>\n\u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> One click in Volixta updates your site to HTTPS safely.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>How do I force HTTPS with 301 redirects?\u003C\u002Fstrong>\u003Cbr \u002F>\n\u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Volixta inserts a safe \u003Ccode>.htaccess\u003C\u002Fcode> redirect or uses a PHP fallback.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>My Site Health report says “No security headers detected”.\u003C\u002Fstrong>\u003Cbr \u002F>\n\u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Apply modern \u003Cstrong>security headers\u003C\u002Fstrong> in one click.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>How can I add WordPress security headers without editing code?\u003C\u002Fstrong>\u003Cbr \u002F>\n\u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Configure and apply headers from the plugin interface.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>After enabling SSL, my site still shows mixed content errors.\u003C\u002Fstrong>\u003Cbr \u002F>\n\u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Run the Mixed Content Scan + Fixer.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>I’m on Nginx, so .htaccess doesn’t work.\u003C\u002Fstrong>\u003Cbr \u002F>\n\u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Volixta provides ready-to-copy Nginx configuration snippets.\u003C\u002Fp>\n\u003Ch3>Privacy\u003C\u002Fh3>\n\u003Cp>This plugin does not collect, store, or transmit personal data.\u003C\u002Fp>\n\u003Ch3>Localization\u003C\u002Fh3>\n\u003Cp>Text domain: \u003Ccode>volixta-ssl-security-headers\u003C\u002Fcode>\u003Cbr \u002F>\nLoad path: \u003Ccode>\u002Flanguages\u003C\u002Fcode>\u003C\u002Fp>\n\u003Ch3>What’s Next\u003C\u002Fh3>\n\u003Cp>If you like this plugin, check out our other tools:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fvolixta.com\" rel=\"nofollow ugc\">VOLIXTA Booking – The All-in-One WordPress Booking Plugin\u003C\u002Fa>\u003Cbr \u002F>\nManage unlimited staff, services, clients, payments, and locations in one powerful system.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fvolixta.com\u002Fvolixta-security-suite\" rel=\"nofollow ugc\">VOLIXTA Security Suite – Advanced WordPress Security Made Simple\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n","Add modern security headers, enable SSL\u002FHTTPS, fix mixed content, and force 301 redirects for WordPress. Fast, safe, and easy to use.",60,1030,3,"2026-05-20T23:59:00.000Z","5.8","7.4",[20,74,21,22],"mixed-content","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvolixta-ssl-security-headers.1.1.5.zip",{"slug":77,"name":78,"version":79,"author":80,"author_profile":81,"description":82,"short_description":83,"active_installs":84,"downloaded":85,"rating":86,"num_ratings":87,"last_updated":88,"tested_up_to":14,"requires_at_least":15,"requires_php":52,"tags":89,"homepage":93,"download_link":94,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"https-redirection","Easy HTTPS Redirection (SSL)","2.0.1","mra13 \u002F Team Tips and Tricks HQ","https:\u002F\u002Fprofiles.wordpress.org\u002Fmra13\u002F","\u003Ch4>Only use this plugin if you have installed SSL certificate on your site and HTTPS is working correctly\u003C\u002Fh4>\n\u003Cp>Once you’ve installed an SSL certificate on your site, it’s important to ensure that your webpages are accessed via their secure HTTPS URLs.\u003C\u002Fp>\n\u003Cp>To improve SEO and user security, you want search engines and visitors to always use the HTTPS version of your pages. This plugin makes that easy by automatically redirecting users to the HTTPS version whenever they try to access the non-HTTPS (HTTP) version of a page.\u003C\u002Fp>\n\u003Ch3>Example\u003C\u002Fh3>\n\u003Cp>Let’s say you want to ensure the following page is always accessed over HTTPS:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>https:\u002F\u002Fwww.example.com\u002Fcheckout\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>If a visitor tries to access:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>http:\u002F\u002Fwww.example.com\u002Fcheckout\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>The plugin will automatically redirect them to the secure version:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>https:\u002F\u002Fwww.example.com\u002Fcheckout\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>This ensures that visitors always access the HTTPS version of your pages or site.\u003C\u002Fp>\n\u003Cp>You can choose to automatically redirect your entire domain to HTTPS, or selectively apply HTTPS redirection to specific pages.\u003C\u002Fp>\n\u003Ch3>Video Tutorials\u003C\u002Fh3>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FoyJgRFCM6u8?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FLtyBraB64v8?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Ch3>Force Load Static Files Using HTTPS\u003C\u002Fh3>\n\u003Cp>If you started using SSL from day 1 of your site then all your static files are already embedded using HTTPS URL. You have no issue there.\u003C\u002Fp>\n\u003Cp>However, if you have an existing website where you have a lot of static files that are embedded in your posts and pages using NON-HTTPS URL then you will need to change those. Otherwise, the browser will show an SSL warning to your visitors.\u003C\u002Fp>\n\u003Cp>This plugin has an option that will allow you to force load those static files using HTTPS URL dynamically.\u003C\u002Fp>\n\u003Cp>This will help you make the webpage fully compatible with SSL.\u003C\u002Fp>\n\u003Ch3>Mixed Content Scanner & Database URL Fixer\u003C\u002Fh3>\n\u003Cp>After switching to HTTPS, your pages can still trigger browser “mixed content” warnings if old HTTP URLs remain saved in your database (in post content, custom post types, post meta, or WordPress options). This plugin includes a built-in scanner to find and update those insecure URLs to their HTTPS version – no manual database editing required.\u003C\u002Fp>\n\u003Cp>Available from the \u003Cstrong>Mixed Contents\u003C\u002Fstrong> settings tab, the scanner lets you:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Scan selected post types\u003C\u002Fstrong> – Choose exactly which post types to scan and update, including posts, pages, and any custom post types registered by your other plugins (products, orders, downloads, subscriptions, and more).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Update other database tables\u003C\u002Fstrong> – Optionally include the WordPress options table in the scan.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Include post meta\u003C\u002Fstrong> – Extend the scan to post meta for the selected post types.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Choose your scan scope\u003C\u002Fstrong> – Run a quick “Scan Static Resources Only” pass, or a thorough “Scan All” to catch every non-HTTPS reference.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This makes cleaning up legacy HTTP links straightforward, helping you achieve a fully secure padlock with no mixed content errors.\u003C\u002Fp>\n\u003Ch3>SSL Certificate Expiry Notification\u003C\u002Fh3>\n\u003Cp>This plugin includes a feature that allows you to receive email notifications when your SSL certificate is about to expire. It helps ensure your website remains secure and accessible over HTTPS.\u003C\u002Fp>\n\u003Cp>You can configure the recipient email address and specify how many days in advance the notification should be sent. By default, the notification is sent 7 days before expiry, but you can adjust this to suit your preference.\u003C\u002Fp>\n\u003Cp>This feature is especially useful for site owners who may not frequently check their SSL status, or for those managing multiple websites. By receiving timely alerts, you can renew your SSL certificate in advance and prevent potential downtime or security warnings.\u003C\u002Fp>\n\u003Ch3>HTTP Strict Transport Security (HSTS) Support\u003C\u002Fh3>\n\u003Cp>Easy HTTPS Redirection includes built-in support for sending the HTTP Strict Transport Security (HSTS) response header.\u003C\u002Fp>\n\u003Cp>HSTS instructs compatible web browsers to automatically access your website over HTTPS after a visitor has successfully visited your secure site. This helps strengthen your site’s HTTPS enforcement and reduces the risk of users accidentally accessing the HTTP version of your website.\u003C\u002Fp>\n\u003Cp>The plugin allows you to:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Enable or disable the HSTS response header with a simple checkbox.\u003C\u002Fli>\n\u003Cli>Configure the HSTS max-age value.\u003C\u002Fli>\n\u003Cli>Apply the HSTS policy to all subdomains using the \u003Ccode>includeSubDomains\u003C\u002Fcode> directive.\u003C\u002Fli>\n\u003Cli>Include the \u003Ccode>preload\u003C\u002Fcode> directive for sites that intend to submit their domain to the browser HSTS preload list.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Automatically redirect all HTTP traffic to HTTPS\u003C\u002Fli>\n\u003Cli>Option to force HTTPS on the entire site\u003C\u002Fli>\n\u003Cli>Option to selectively apply HTTPS redirection to specific pages\u003C\u002Fli>\n\u003Cli>Helps search engines index the secure versions of your pages\u003C\u002Fli>\n\u003Cli>Improves site security and user trust\u003C\u002Fli>\n\u003Cli>Force load static files (images, js, css etc) using a HTTPS URL\u003C\u002Fli>\n\u003Cli>Built-in mixed content scanner to find and update non-HTTPS URLs across post content, post meta, custom post types, and WordPress options\u003C\u002Fli>\n\u003Cli>SSL certificate expiry notification – Option to send SSL expiry notifications to a specific email address\u003C\u002Fli>\n\u003Cli>Easily see which SSL certificates on your site are approaching their expiry date.\u003C\u002Fli>\n\u003Cli>HTTP Strict Transport Security (HSTS) support with configurable max-age, includeSubDomains, and preload options.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>View more details on the \u003Ca href=\"https:\u002F\u002Fwww.tipsandtricks-hq.com\u002Fwordpress-easy-https-redirection-plugin\" rel=\"nofollow ugc\">HTTPS Redirection plugin\u003C\u002Fa> page.\u003C\u002Fp>\n","The plugin allows an automatic redirection to the \"HTTPS\" version\u002FURL of the site. Make your site SSL compatible easily.",100000,1239012,84,71,"2026-06-30T15:10:00.000Z",[90,20,91,92,22],"force-ssl","insecure-content","redirection","https:\u002F\u002Fwww.tipsandtricks-hq.com\u002Fwordpress-easy-https-redirection-plugin","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fhttps-redirection.2.0.1.zip",{"slug":96,"name":97,"version":98,"author":99,"author_profile":100,"description":101,"short_description":102,"active_installs":84,"downloaded":103,"rating":104,"num_ratings":105,"last_updated":106,"tested_up_to":14,"requires_at_least":107,"requires_php":108,"tags":109,"homepage":111,"download_link":112,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"ssl-insecure-content-fixer","SSL Insecure Content Fixer","2.7.2","webaware","https:\u002F\u002Fprofiles.wordpress.org\u002Fwebaware\u002F","\u003Cp>Clean up your WordPress website’s HTTPS insecure content and mixed content warnings. Installing the SSL Insecure Content Fixer plugin will solve most insecure content warnings with little or no effort. The remainder can be diagnosed with a few simple tools.\u003C\u002Fp>\n\u003Cp>When you install SSL Insecure Content Fixer, its default settings are activated and it will automatically perform some basic fixes on your website using the Simple fix level. You can select more comprehensive fix levels as needed by your website.\u003C\u002Fp>\n\u003Cp>WordPress Multisite gets a network settings page. This can be used to set default settings for all sites within a network, so that network administrators only need to specify settings on sites that have requirements differing from the network defaults.\u003C\u002Fp>\n\u003Cp>See the \u003Ca href=\"https:\u002F\u002Fssl.webaware.net.au\u002F\" rel=\"nofollow ugc\">SSL Insecure Content Fixer website\u003C\u002Fa> for more details.\u003C\u002Fp>\n\u003Ch3>Translations\u003C\u002Fh3>\n\u003Cp>Many thanks to the generous efforts of our translators:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Bulgarian (bg_BG) — \u003Ca href=\"https:\u002F\u002Ftranslate.wordpress.org\u002Flocale\u002Fbg\u002Fdefault\u002Fwp-plugins\u002Fssl-insecure-content-fixer\" rel=\"nofollow ugc\">the Bulgarian translation team\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Chinese simplified (zh_CN) — \u003Ca href=\"https:\u002F\u002Ftranslate.wordpress.org\u002Flocale\u002Fzh-cn\u002Fdefault\u002Fwp-plugins\u002Fssl-insecure-content-fixer\" rel=\"nofollow ugc\">the Chinese translation team\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>English (en_CA) — \u003Ca href=\"https:\u002F\u002Ftranslate.wordpress.org\u002Flocale\u002Fen-ca\u002Fdefault\u002Fwp-plugins\u002Fssl-insecure-content-fixer\" rel=\"nofollow ugc\">the English (Canadian) translation team\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>English (en_GB) — \u003Ca href=\"https:\u002F\u002Ftranslate.wordpress.org\u002Flocale\u002Fen-gb\u002Fdefault\u002Fwp-plugins\u002Fssl-insecure-content-fixer\" rel=\"nofollow ugc\">the English (British) translation team\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>English (en_ZA) — \u003Ca href=\"https:\u002F\u002Ftranslate.wordpress.org\u002Flocale\u002Fen-za\u002Fdefault\u002Fwp-plugins\u002Fssl-insecure-content-fixer\" rel=\"nofollow ugc\">the English (South African) translation team\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Dutch (nl_NL) — \u003Ca href=\"https:\u002F\u002Ftranslate.wordpress.org\u002Flocale\u002Fnl\u002Fdefault\u002Fwp-plugins\u002Fssl-insecure-content-fixer\" rel=\"nofollow ugc\">the Dutch translation team\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>German (de_DE) — \u003Ca href=\"https:\u002F\u002Ftranslate.wordpress.org\u002Flocale\u002Fde\u002Fdefault\u002Fwp-plugins\u002Fssl-insecure-content-fixer\" rel=\"nofollow ugc\">the German translation team\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>French (fr_FR) — \u003Ca href=\"https:\u002F\u002Ftranslate.wordpress.org\u002Flocale\u002Ffr\u002Fdefault\u002Fwp-plugins\u002Fssl-insecure-content-fixer\" rel=\"nofollow ugc\">the French translation team\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Italian (it_IT) — \u003Ca href=\"https:\u002F\u002Ftranslate.wordpress.org\u002Flocale\u002Fit\u002Fdefault\u002Fwp-plugins\u002Fssl-insecure-content-fixer\" rel=\"nofollow ugc\">the Italian translation team\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Japanese (ja) — \u003Ca href=\"https:\u002F\u002Ftranslate.wordpress.org\u002Flocale\u002Fja\u002Fdefault\u002Fwp-plugins\u002Fssl-insecure-content-fixer\" rel=\"nofollow ugc\">the Japanese translation team\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Russian (ru_RU) — \u003Ca href=\"https:\u002F\u002Ftranslate.wordpress.org\u002Flocale\u002Fru\u002Fdefault\u002Fwp-plugins\u002Fssl-insecure-content-fixer\" rel=\"nofollow ugc\">the Russian translation team\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Spanish (es_ES) — \u003Ca href=\"https:\u002F\u002Ftranslate.wordpress.org\u002Flocale\u002Fes\u002Fdefault\u002Fwp-plugins\u002Fssl-insecure-content-fixer\" rel=\"nofollow ugc\">the Spanish translation team\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>If you’d like to help out by translating this plugin, please \u003Ca href=\"https:\u002F\u002Ftranslate.wordpress.org\u002Fprojects\u002Fwp-plugins\u002Fssl-insecure-content-fixer\" rel=\"nofollow ugc\">sign up for an account and dig in\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>Privacy\u003C\u002Fh3>\n\u003Cp>SSL Insecure Content Fixer does not collect any personally identifying information, and does not set any cookies.\u003C\u002Fp>\n","Clean up WordPress website HTTPS insecure content",2666646,96,221,"2026-05-12T05:29:00.000Z","4.0","5.3",[20,91,74,110,22],"partially-encrypted","https:\u002F\u002Fssl.webaware.net.au\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fssl-insecure-content-fixer.2.7.2.zip",{"slug":114,"name":115,"version":116,"author":117,"author_profile":118,"description":119,"short_description":120,"active_installs":121,"downloaded":122,"rating":34,"num_ratings":123,"last_updated":124,"tested_up_to":14,"requires_at_least":125,"requires_php":126,"tags":127,"homepage":129,"download_link":130,"security_score":25,"vuln_count":32,"unpatched_count":11,"last_vuln_date":131,"fetched_at":27},"wp-force-ssl","WP Force SSL & HTTPS SSL Redirect","1.70","WebFactory","https:\u002F\u002Fprofiles.wordpress.org\u002Fwebfactory\u002F","\u003Cp>\u003Ca href=\"https:\u002F\u002Fwpforcessl.com\u002F?ref=wporg\" rel=\"nofollow ugc\">WP Force SSL\u003C\u002Fa> helps you redirect insecure HTTP traffic to secure HTTPS and fix SSL errors \u003Cstrong>without touching any code\u003C\u002Fstrong>. Activate Force SSL and everything will be set and SSL enabled. The entire site will move to HTTPS using your SSL certificate. It works with any SSL certificate. It can be free SSL certificate from Let’s Encrypt or a paid SSL certificate.\u003C\u002Fp>\n\u003Cp>How to add SSL & enable SSL? Most hosting companies support the free SSL certificate from Let’s Encrypt, so login to your hosting panel and add SSL certificate. You’ll see a button labeled “Add SSL Certificate” or “Add Let’s Encrypt Certificate” and after that it’s 1 click to have the SSL enabled on your site with WP Force SSL. If that doesn’t work get \u003Ca href=\"https:\u002F\u002Fwpforcessl.com\u002F\" rel=\"nofollow ugc\">WP Force SSL PRO\u003C\u002Fa> and it’ll generate free SSL certificate for your site. And will regenerate SSL certificate every 90 days.\u003C\u002Fp>\n\u003Cp>Access WP Force SSL settings via the main Settings menu -> WP Force SSL.\u003C\u002Fp>\n\u003Ch4>SSL Tests available in the plugin\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>is site on localhost?\u003C\u002Fli>\n\u003Cli>check SSL certificate\u003C\u002Fli>\n\u003Cli>check SSL certificate expiry date\u003C\u002Fli>\n\u003Cli>is latest version of Force SSL used?\u003C\u002Fli>\n\u003Cli>are known incompatible SSL plugins active?\u003C\u002Fli>\n\u003Cli>is WP address URL set for SSL?\u003C\u002Fli>\n\u003Cli>is WP home URL set for SSL?\u003C\u002Fli>\n\u003Cli>is SSL monitoring enabled (pro feature)\u003C\u002Fli>\n\u003Cli>is HTTPS redirection working?\u003C\u002Fli>\n\u003Cli>is file redirection working (pro feature)\u003C\u002Fli>\n\u003Cli>is HSTS enabled?\u003C\u002Fli>\n\u003Cli>check mixed-content issue (pro feature)\u003C\u002Fli>\n\u003Cli>is htaccess available & writable?\u003C\u002Fli>\n\u003Cli>is 404 redirection enabled (pro feature)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Settings\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>redirect HTTP to HTTPS\u003C\u002Fli>\n\u003Cli>fix mixed-content (pro)\u003C\u002Fli>\n\u003Cli>enable HSTS\u003C\u002Fli>\n\u003Cli>force secure cookies (pro)\u003C\u002Fli>\n\u003Cli>cross-site scripting protection (pro)\u003C\u002Fli>\n\u003Cli>expect CT header\u003C\u002Fli>\n\u003Cli>X-Frame options\u003C\u002Fli>\n\u003Cli>show WP Force SSL menu in admin bar\u003C\u002Fli>\n\u003Cli>show WP Force SSL widget in admin dashboard\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>SSL certificate testing tool\u003C\u002Fh4>\n\u003Cp>WP Force SSL comes with an SSL certificate testing tool. It tests if the SSL certificate is valid, properly installed & up-to date.\u003C\u002Fp>\n\u003Ch4>Need support?\u003C\u002Fh4>\n\u003Cp>We’re here for you! Things get frustrating when they don’t work so make sure you \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fwp-force-ssl\u002F\" rel=\"ugc\">open a support topic\u003C\u002Fa> in the official Force SSL forum. We answer all questions within a few hours!\u003C\u002Fp>\n\u003Ch4>External Assets\u003C\u002Fh4>\n\u003Cp>A big thank you to \u003Ca href=\"https:\u002F\u002Fsweetalert2.github.io\u002F\" rel=\"nofollow ugc\">SweetAlert2\u003C\u002Fa> authors which we use to make alerts nicer. And to \u003Ca href=\"https:\u002F\u002Fdepositphotos.com\u002F248496280\u002Fstock-illustration-online-payment-protection-system-concept.html\" rel=\"nofollow ugc\">DepositPhotos\u003C\u002Fa> for the lovely header image.\u003C\u002Fp>\n","Enable SSL & HTTPS redirect with 1 click! Add SSL certificate & WP Force SSL to redirect site from HTTP to HTTPS & fix SSL errors.",90000,1835602,179,"2026-07-20T05:44:00.000Z","4.6","5.2",[90,20,74,22,128],"ssl-certificate","https:\u002F\u002Fwpforcessl.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-force-ssl.1.70.zip","2024-06-07 00:00:00",{"error":133,"url":134,"statusCode":135,"statusMessage":136,"message":136},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fzen-site-security\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":32,"versions":138},[139],{"version":6,"download_url":24,"svn_tag_url":140,"released_at":26,"has_diff":141,"diff_files_changed":142,"diff_lines":26,"trac_diff_url":26,"vulnerabilities":143,"is_current":133},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fzen-site-security\u002Ftags\u002F1.13.1\u002F",false,[],[]]