Title: 360 Orbit Header Security
Author: Jörg Liwa
Published: <strong>2026년 10월 6일</strong>
Last modified: 2026년 10월 7일

---

플러그인 검색

![](https://ps.w.org/360-orbit-header-security/assets/banner-772x250.png?rev=3730102)

![](https://ps.w.org/360-orbit-header-security/assets/icon.svg?rev=3730102)

# 360 Orbit Header Security

 작성자: [Jörg Liwa](https://profiles.wordpress.org/joergliwa/)

[다운로드](https://downloads.wordpress.org/plugin/360-orbit-header-security.1.0.28.zip)

 * [세부사항](https://ko.wordpress.org/plugins/360-orbit-header-security/#description)
 * [평가](https://ko.wordpress.org/plugins/360-orbit-header-security/#reviews)
 *  [설치](https://ko.wordpress.org/plugins/360-orbit-header-security/#installation)
 * [개발](https://ko.wordpress.org/plugins/360-orbit-header-security/#developers)

 [지원](https://wordpress.org/support/plugin/360-orbit-header-security/)

## 설명

Header Security brings your website up to date with current HTTP security headers:

 * Strict-Transport-Security (HSTS)
 * X-Frame-Options and CSP frame-ancestors (clickjacking protection, even without
   a full CSP)
 * X-Content-Type-Options
 * Referrer-Policy
 * Permissions-Policy
 * Cross-Origin-Opener-Policy / Cross-Origin-Resource-Policy
 * Cookie hardening: adds missing Secure and SameSite attributes to all cookies 
   the website sends
 * Optional 301 redirect from HTTP to HTTPS

Each header can be switched on and off individually, and its values are fully configurable.
A quickstart button enables the recommended settings with a single click.

#### Free vs. Pro

The free version fully covers all of the basic headers listed above for the frontend.

**Header Security Pro** adds:

 * Content Security Policy (CSP), including a report-only mode for a low-risk start.
 * Learning mode: collects everything the CSP would block for a configurable period
   and only switches to enforcing once no finding is left unreviewed.
 * A scanner that automatically detects the external services your site needs (scripts,
   styles, images, fonts, iframes) and presents them for approval, including bulk
   approve/block.
 * Separate header configuration for the backend (wp-admin); WordPress’s own services
   are allowed automatically.
 * One address for your site: redirects the other spelling (with or without “www.”)
   to the address set in WordPress.
 * Option to load http:// sub-resources over https (upgrade-insecure-requests) as
   part of the Content Security Policy.
 * Automatic update notifications directly in the WordPress backend.

## 스크린샷

[⌊Status overview (free version) with the quickstart button. The Content Security
Policy and the backend configuration are Pro features.⌉⌊Status overview (free version)
with the quickstart button. The Content Security Policy and the backend configuration
are Pro features.⌉[

Status overview (free version) with the quickstart button. The Content Security 
Policy and the backend configuration are Pro features.

## 설치

 1. Install the plugin under _Plugins > Add New_ (search for “360 Orbit Header Security”),
    or upload the ZIP under _Plugins > Add New > Upload Plugin_.
 2. Activate the plugin.
 3. In the **Header Security** menu, click “Run quickstart” or configure the headers
    individually.

## FAQ

### Can I accidentally break my website with this?

The quickstart defaults are deliberately cautious (for example, X-Frame-Options:
SAMEORIGIN instead of DENY, so the WordPress Customizer keeps working). The Content
Security Policy (Pro) starts in report-only mode by default, which does not block
anything and only reports.

### Do I have to use a Content Security Policy?

No. CSP is optional and only available in the Pro version anyway. The basic headers
of the free version work independently of it.

### Who is liable in case of damage?

This plugin is provided without any warranty (“as is”). The developer accepts no
liability for data loss or damage resulting from the use of the plugin (for example,
from an overly restrictive header configuration). Before using it, you are strongly
advised to create a full backup and to test changes in report-only mode first.

### Does the plugin change files or contact other servers?

By default it only sends headers from PHP. Optionally you can switch on the “.htaccess
mirror”: the plugin then writes its own marked block into your `.htaccess` (so the
headers also reach cached pages) and tests your homepage with a request to your 
own site, rolling back automatically if the site stops responding. While that block
exists, the plugin also keeps a small guard file in `wp-content/mu-plugins/` that
removes the block should the plugin folder ever be deleted without deactivating 
it; deactivating or deleting the plugin removes both. No data is sent to any other
server.

### Does it work on multisite?

The headers work on every site. Because the `.htaccess` file is shared by the whole
network, only a super admin can use the “.htaccess mirror” on multisite.

### Which languages is the backend available in?

The backend follows the language set in WordPress. Translations are provided through
translate.wordpress.org and you are welcome to contribute one for your language.

## 후기

이 플러그인에 대한 평가가 없습니다.

## 기여자 & 개발자

“360 Orbit Header Security”(은)는 오픈 소스 소프트웨어입니다. 다음의 사람들이 이
플러그인에 기여하였습니다.

기여자

 *   [ Jörg Liwa ](https://profiles.wordpress.org/joergliwa/)

[자국어로 “360 Orbit Header Security”(을)를 번역하세요.](https://translate.wordpress.org/projects/wp-plugins/360-orbit-header-security)

### 개발에 관심이 있으십니까?

[코드 탐색하기](https://plugins.trac.wordpress.org/browser/360-orbit-header-security/)
는, [SVN 저장소](https://plugins.svn.wordpress.org/360-orbit-header-security/)를
확인하시거나, [개발 기록](https://plugins.trac.wordpress.org/log/360-orbit-header-security/)
을 [RSS](https://plugins.trac.wordpress.org/log/360-orbit-header-security/?limit=100&mode=stop_on_copy&format=rss)
로 구독하세요.

## 변경이력

#### 1.0.28

 * The 360 WP Orbit overview now also lists the new plugin 360 Orbit Database Cleaner.

## 기초

 *  버전 **1.0.28**
 *  최근 업데이트: **2시간 전**
 *  활성화된 설치 **10보다 적음**
 *  워드프레스 버전 ** 6.4 또는 그 이상 **
 *  다음까지 시험됨: **7.1.3**
 *  PHP 버전 ** 8.1 또는 그 이상 **
 *  언어
 * [English (US)](https://wordpress.org/plugins/360-orbit-header-security/)
 * 태그:
 * [clickjacking](https://ko.wordpress.org/plugins/tags/clickjacking/)[hsts](https://ko.wordpress.org/plugins/tags/hsts/)
   [http-headers](https://ko.wordpress.org/plugins/tags/http-headers/)[security](https://ko.wordpress.org/plugins/tags/security/)
   [Security Headers](https://ko.wordpress.org/plugins/tags/security-headers/)
 *  [고급 보기](https://ko.wordpress.org/plugins/360-orbit-header-security/advanced/)

## 평점

아직 제출된 리뷰가 없습니다.

[Your review](https://wordpress.org/support/plugin/360-orbit-header-security/reviews/#new-post)

[모든  리뷰 보기](https://wordpress.org/support/plugin/360-orbit-header-security/reviews/)

## 기여자

 *   [ Jörg Liwa ](https://profiles.wordpress.org/joergliwa/)

## 지원

할 말 있으신가요? 도움이 필요하신가요?

 [지원 포럼 보기](https://wordpress.org/support/plugin/360-orbit-header-security/)