Title: Beplus Security Headers &amp; Script Auditor
Author: rimbeplus
Published: <strong>19 août 2026</strong>
Last modified: 19 août 2026

---

Recherche d’extensions

![](https://ps.w.org/beplus-security-headers-script-auditor/assets/banner-772x250.
png?rev=3654344)

![](https://ps.w.org/beplus-security-headers-script-auditor/assets/icon-256x256.
png?rev=3654344)

# Beplus Security Headers & Script Auditor

 Par [rimbeplus](https://profiles.wordpress.org/rimbeplus/)

[Télécharger](https://downloads.wordpress.org/plugin/beplus-security-headers-script-auditor.1.0.0.zip)

 * [Détails](https://fr.wordpress.org/plugins/beplus-security-headers-script-auditor/#description)
 * [Avis](https://fr.wordpress.org/plugins/beplus-security-headers-script-auditor/#reviews)
 *  [Installation](https://fr.wordpress.org/plugins/beplus-security-headers-script-auditor/#installation)
 * [Développement](https://fr.wordpress.org/plugins/beplus-security-headers-script-auditor/#developers)

 [Support](https://wordpress.org/support/plugin/beplus-security-headers-script-auditor/)

## Description

Beplus Security Headers & Script Auditor gives WordPress site owners three things
in one screen:

 1. **Security header toggles** — enable X-Frame-Options, X-Content-Type-Options, Referrer-
    Policy, Strict-Transport-Security, Permissions-Policy, Content-Security-Policy (
    with an optional report-only mode), and the legacy X-XSS-Protection header, each
    with sensible defaults.
 2. **A scanner** — fetches your homepage, or optionally your whole site (up to 200
    of your most recently published posts/pages), and lists every external script, 
    stylesheet, image, iframe, and form target it finds, plus a count of inline scripts/
    styles.
 3. **Recommendations you control** — every finding is listed as a checkbox row; uncheck
    anything you don’t want, and the Content-Security-Policy preview updates live. 
    Apply the checked rows to the CSP field with one click, review it, then press Save.
    Nothing is ever sent automatically.

There’s also a repeatable table for adding any other custom response header your
site needs.

#### Why use this plugin

 * No external service calls, tracking, or phone-home behaviour — the scan only 
   requests pages on your own site.
 * Every setting is sanitized on save, and header values are stripped of line breaks
   to prevent HTTP header injection.
 * Sensible, conservative defaults: only X-Frame-Options, X-Content-Type-Options,
   and Referrer-Policy are enabled out of the box. HSTS, Permissions-Policy, CSP,
   and X-XSS-Protection are opt-in since they can affect how your site behaves and
   should be reviewed first.

## Captures d’écrans

[⌊The Headers tab, where each security header can be toggled and configured.⌉⌊The
Headers tab, where each security header can be toggled and configured.⌉[

The Headers tab, where each security header can be toggled and configured.

[⌊The Scanner tab, showing detected external resources as a checklist and a live
Content-Security-Policy preview.⌉⌊The Scanner tab, showing detected external resources
as a checklist and a live Content-Security-Policy preview.⌉[

The Scanner tab, showing detected external resources as a checklist and a live Content-
Security-Policy preview.

## Installation

 1. Upload the plugin files to the `/wp-content/plugins/beplus-security-headers-script-
    auditor` directory, or install the plugin through the WordPress plugins screen 
    directly.
 2. Activate the plugin through the ‘Plugins’ screen in WordPress.
 3. Go to the « Security Headers » menu item (in the main admin sidebar) to review 
    the default header configuration.
 4. Open the Scanner tab and click « Run Scan » (optionally ticking « Scan entire site»
    first) to see what external resources your site loads, uncheck anything you don’t
    want, then apply the checked rows to the Content-Security-Policy field.
 5. Click « Save Changes » to apply your configuration.

## FAQ

### Will this break my site if I enable everything at once?

It can, especially Content-Security-Policy. Start with the scanner recommendations,
use « Report-only mode » for CSP first to observe without blocking anything, and
only switch to enforcing mode once you’ve confirmed the policy covers everything
your site actually loads.

### Does the scanner send my data anywhere?

No. It performs normal HTTP requests from your own server to pages on your own site,
using the built-in WordPress HTTP API. Nothing is sent to any third party.

### Does this replace a full security audit?

No. Even the whole-site option only scans your homepage plus your most recently 
published posts/pages (capped at 200) and is meant as a starting point for building
a Content-Security-Policy, not a substitute for a complete security review of your
site.

## Avis

Il n’y a aucun avis pour cette extension.

## Contributeurs/contributrices & développeurs/développeuses

« Beplus Security Headers & Script Auditor » est un logiciel libre. Les personnes
suivantes ont contribué à cette extension.

Contributeurs

 *   [ rimbeplus ](https://profiles.wordpress.org/rimbeplus/)

[Traduisez « Beplus Security Headers & Script Auditor » dans votre langue.](https://translate.wordpress.org/projects/wp-plugins/beplus-security-headers-script-auditor)

### Le développement vous intéresse ?

[Parcourir le code](https://plugins.trac.wordpress.org/browser/beplus-security-headers-script-auditor/),
consulter le [SVN dépôt](https://plugins.svn.wordpress.org/beplus-security-headers-script-auditor/),
ou s’inscrire au [journal de développement](https://plugins.trac.wordpress.org/log/beplus-security-headers-script-auditor/)
par [RSS](https://plugins.trac.wordpress.org/log/beplus-security-headers-script-auditor/?limit=100&mode=stop_on_copy&format=rss).

## Journal des modifications

#### 1.0.0

 * Initial release: security header toggles, homepage/whole-site scanner with a 
   pick-and-choose CSP checklist, and custom header repeater.

## Méta

 *  Version **1.0.0**
 *  Dernière mise à jour **il y a 2 jours**
 *  Installations actives **Moins de 10**
 *  Version de WordPress ** 6.0 ou plus **
 *  Testé jusqu’à **7.1**
 *  Version de PHP ** 7.4 ou plus **
 *  Langue
 * [English (US)](https://wordpress.org/plugins/beplus-security-headers-script-auditor/)
 * Étiquettes
 * [content security policy](https://fr.wordpress.org/plugins/tags/content-security-policy/)
   [csp](https://fr.wordpress.org/plugins/tags/csp/)[headers](https://fr.wordpress.org/plugins/tags/headers/)
   [http-headers](https://fr.wordpress.org/plugins/tags/http-headers/)[security](https://fr.wordpress.org/plugins/tags/security/)
 *  [Vue avancée](https://fr.wordpress.org/plugins/beplus-security-headers-script-auditor/advanced/)

## Évaluations

Aucun avis n’a encore été envoyé.

[Votre avis](https://wordpress.org/support/plugin/beplus-security-headers-script-auditor/reviews/#new-post)

[Tout voir](https://wordpress.org/support/plugin/beplus-security-headers-script-auditor/reviews/)

## Contributeurs

 *   [ rimbeplus ](https://profiles.wordpress.org/rimbeplus/)

## Support

Quelque chose à dire ? Besoin d’aide ?

 [Voir le forum de support](https://wordpress.org/support/plugin/beplus-security-headers-script-auditor/)