Title: Volixta SSL &amp; Security Headers
Author: VOLIXTA TEAM
Published: <strong>2 اکتبر 2025</strong>
Last modified: 23 آگوست 2026

---

جستجوی افزونه‌ها

![](https://ps.w.org/volixta-ssl-security-headers/assets/banner-772×250.png?rev=
3371933)

![](https://ps.w.org/volixta-ssl-security-headers/assets/icon-256x256.png?rev=3371933)

# Volixta SSL & Security Headers

 توسط [VOLIXTA TEAM](https://profiles.wordpress.org/volixta/)

[دانلود](https://downloads.wordpress.org/plugin/volixta-ssl-security-headers.1.3.4.zip)

 * [جزئیات](https://fa.wordpress.org/plugins/volixta-ssl-security-headers/#description)
 * [نقد و بررسی‌ها](https://fa.wordpress.org/plugins/volixta-ssl-security-headers/#reviews)
 *  [نصب](https://fa.wordpress.org/plugins/volixta-ssl-security-headers/#installation)
 * [توسعه](https://fa.wordpress.org/plugins/volixta-ssl-security-headers/#developers)

 [پشتیبانی](https://wordpress.org/support/plugin/volixta-ssl-security-headers/)

## توضیحات

**Volixta SSL & Security Headers** helps WordPress site owners configure HTTPS, 
manage SSL certificates, fix mixed content, and apply modern browser security without
manually editing sensitive server files.

Use Volixta to request free **Let’s Encrypt certificates**, install supported certificates
through hosting integrations, switch WordPress to HTTPS, configure **301 redirects**,
and verify the certificate that visitors actually receive.

Key features include:

 * **Let’s Encrypt ACME v2** certificate requests with HTTP-01 validation.
 * **Certificate installation** for supported cPanel, Plesk, and DirectAdmin environments,
   plus downloadable files for manual installation.
 * **Automatic renewal checks** for eligible Volixta-managed production certificates.
 * **HTTPS setup and redirects** with guarded Apache/LiteSpeed `.htaccess` changes
   and Nginx guidance.
 * **Mixed Content tools** including frontend checks, Deep Scan, Live Fixer, and
   serialization-safe database cleanup.
 * **Security Headers** including HSTS, CSP, CSP Report-Only, X-Content-Type-Options,
   Referrer-Policy, Permissions-Policy, COOP, COEP, and CORP.
 * **Secure Cookies** for WordPress authentication and PHP sessions with Secure,
   HttpOnly, and SameSite=Lax protection.
 * **CSP Report-Only monitoring** with capped local reports and rate limiting.
 * **Safety Backups** before managed `.htaccess` changes. `wp-config.php` backups
   are downloaded directly to your computer and are not stored by Volixta on the
   server.
 * **Site Health integration** for important SSL, HTTPS, redirect, cookie, and header
   checks.
 * **Hosting-aware guidance** for Apache, LiteSpeed, Nginx, reverse proxies, Cloudflare,
   localhost, and manual certificate workflows.

Volixta is designed to fail safely: it uses marked configuration blocks, verifies
backups and file snapshots, and avoids overwriting unrelated `.htaccess` content.

### Privacy

Volixta SSL & Security Headers does not include analytics, usage tracking, or visitor
tracking.

The plugin stores the configuration required for enabled features inside your WordPress
installation. When CSP Report-Only monitoring is enabled, Volixta stores a capped
local history of CSP violation diagnostics. It does not store visitor IP addresses,
user agents, referrers, or CSP script samples in that report history.

Some actions communicate with external services when you explicitly use features
that require them. CSP violation monitoring uses a local WordPress REST endpoint
and does not send those reports to a third-party reporting service.

Examples include:

 * **Let’s Encrypt**: certificate requests and ACME validation.
 * **Hosting integrations**: configured cPanel, Plesk, or DirectAdmin connections
   used for certificate installation.

Only information required to perform the requested operation is sent to those services.

### Localization

Text domain: `volixta-ssl-security-headers`
 Load path: `/languages`

### What’s Next

If you like this plugin, check out our other tools:

 * [VOLIXTA Booking – The All-in-One WordPress Booking Plugin](https://volixta.com)
   
   Manage unlimited staff, services, clients, payments, and locations in one powerful
   system.
 * [VOLIXTA Toolkit – A collection of practical WordPress tools for configuration, maintenance, security, and site management.](https://volixta.com/volixta-security-suite)

## عکس‌های صفحه

[⌊Guided SSL and security setup with score and safety backup⌉⌊Guided SSL and security
setup with score and safety backup⌉[

Guided SSL and security setup with score and safety backup

[⌊HTTPS setup with certificate check and one-click redirect⌉⌊HTTPS setup with certificate
check and one-click redirect⌉[

HTTPS setup with certificate check and one-click redirect

[⌊SSL certificate status, expiry, and certificate tools⌉⌊SSL certificate status,
expiry, and certificate tools⌉[

SSL certificate status, expiry, and certificate tools

[⌊Let’s Encrypt issuance, installation, and renewal⌉⌊Let’s Encrypt issuance, installation,
and renewal⌉[

Let’s Encrypt issuance, installation, and renewal

[⌊SSL file management and .htaccess safety backup⌉⌊SSL file management and .htaccess
safety backup⌉[

SSL file management and `.htaccess` safety backup

[⌊Mixed content scan, fixer, and cleanup tools⌉⌊Mixed content scan, fixer, and cleanup
tools⌉[

Mixed content scan, fixer, and cleanup tools

[⌊Secure Cookie protection for WordPress authentication and PHP sessions⌉⌊Secure
Cookie protection for WordPress authentication and PHP sessions⌉[

Secure Cookie protection for WordPress authentication and PHP sessions

[⌊Recommended security headers with one-click protection⌉⌊Recommended security headers
with one-click protection⌉[

Recommended security headers with one-click protection

[⌊Advanced security headers configuration⌉⌊Advanced security headers configuration⌉[

Advanced security headers configuration

[⌊Content Security Policy configuration with enforcement and Report-Only monitoring⌉⌊
Content Security Policy configuration with enforcement and Report-Only monitoring⌉[

Content Security Policy configuration with enforcement and Report-Only monitoring

## نصب

 1.  Upload the plugin to `/wp-content/plugins/` or install **Volixta SSL & Security
     Headers** from the WordPress plugin directory.
 2.  Activate the plugin.
 3.  Open **Volixta SSL & Security** from the WordPress admin menu.
 4.  Follow the Guided Setup.
 5.  Create a Safety Backup when `.htaccess` changes will be used.
 6.  Detect an existing SSL certificate or request a free Let’s Encrypt certificate
     if needed.
 7.  Install and verify the certificate.
 8.  Activate WordPress HTTPS and enable the HTTPS redirect.
 9.  Check the website for mixed content.
 10. Apply the recommended Security Headers if appropriate for your website.

## سوالات متداول

### Do I need an SSL certificate before using Volixta?

No. Volixta can detect an existing public certificate or request a free Let’s Encrypt
certificate for an eligible public domain.

If your hosting provider already manages SSL, you can continue using that certificate.

### Can Volixta request a free Let’s Encrypt SSL certificate?

Yes. Volixta includes an ACME v2 client and supports Let’s Encrypt certificate requests
using the HTTP-01 challenge.

The domain must be publicly reachable and meet the certificate authority requirements.

### Can Volixta install the SSL certificate automatically?

Yes, when a supported hosting integration is configured.

Volixta supports certificate installation through cPanel, Plesk, and DirectAdmin
integrations.

If automatic installation is unavailable, the generated certificate files remain
available for manual installation.

### Can Volixta renew SSL certificates automatically?

Yes. Eligible Volixta-managed production certificates can be checked through WP-
Cron.

When a certificate reaches the renewal window, Volixta can request and install a
replacement when the required hosting integration is configured.

### How do I activate HTTPS in WordPress?

Once a valid certificate is available, open Volixta and follow the Guided Setup 
or the SSL & HTTPS section.

Volixta can update the WordPress Home URL and Site URL to use HTTPS.

### How do I force HTTP to HTTPS?

Volixta can enable a permanent 301 HTTPS redirect.

On Apache and LiteSpeed, the redirect can be added inside a Volixta-managed `.htaccess`
block.

For Nginx, Volixta provides the configuration that needs to be added to the server.

### Does Volixta replace my .htaccess file?

No. Volixta is designed to manage only its own marked sections inside `.htaccess`.

For example:

 * `# BEGIN Volixta HTTPS Redirect`
 * `# END Volixta HTTPS Redirect`

Rules outside Volixta-managed blocks are preserved by the managed-block writer.

Sensitive operations also use backup and consistency checks. If the file cannot 
be modified safely, Volixta leaves it unchanged.

### What is the Safety Backup?

For .htaccess changes, Volixta can create a recovery copy of the current file before
managed server rules are changed.

For wp-config.php changes, Volixta does not store a backup on the server. Instead,
you can download the current wp-config.php directly to your computer before applying
persistent Secure Cookie settings.

### Does Volixta create automatic .htaccess backups?

Yes. Supported sensitive `.htaccess` operations create an automatic rollback backup
before the file is changed.

You can also create and download a manual Safety Backup.

### What happens to .htaccess when I uninstall Volixta?

Volixta does not intentionally delete or replace the whole `.htaccess` file.

The uninstall process only attempts to remove Volixta-managed blocks.

Before modifying an existing `.htaccess` file during uninstall, a verified recovery
snapshot is required. If that snapshot cannot be created safely, the existing `.
htaccess` file is left unchanged.

### What is mixed content?

Mixed content happens when an HTTPS page still loads one or more resources through
HTTP.

This can include images, scripts, stylesheets, fonts, or embedded resources.

### Does the Mixed Content Scan modify my database?

No. Frontend checks and scans do not permanently modify WordPress content.

Permanent changes are made only when you explicitly use Database Cleanup.

### Is Database Cleanup safe with serialized WordPress data?

Volixta handles eligible serialized WordPress values instead of performing a blind
database-wide text replacement.

As with any permanent database operation, keeping a normal website backup before
cleanup is recommended.

### What does the Live Fixer do?

The Live Fixer upgrades eligible insecure resource URLs while the page is rendered.

It does not permanently change the stored database values.

If your rendered frontend does not contain mixed content, there is normally no need
to enable it.

### Which Security Headers does Volixta support?

Volixta supports common browser protections including HSTS, CSP, X-Frame-Options,
X-Content-Type-Options, Referrer-Policy, Permissions-Policy, COOP, COEP, CORP, and
additional advanced policies.

### Can Security Headers break parts of a website?

Strict browser policies can affect external scripts, embedded content, APIs, media,
fonts, or other resources.

Volixta therefore provides a Recommended configuration and keeps more technical 
controls in the Advanced section.

Review custom policies carefully before applying them to a production website.

### What does Secure Cookie Protection do?

Secure Cookie Protection strengthens WordPress authentication and PHP session cookies
when HTTPS is enabled.

Volixta can enforce Secure protection for WordPress authentication cookies and configure
PHP session cookies with Secure, HttpOnly, and SameSite=Lax settings.

Before persistent changes are made to wp-config.php, Volixta lets you download the
current file directly to your computer. The backup is not stored on the server.

### What is CSP Report-Only monitoring?

CSP Report-Only lets you test a Content Security Policy without blocking website
resources.

Browsers report policy violations to a local Volixta endpoint so you can identify
scripts, images, connections, or other resources that would be affected before enforcing
the policy.

Volixta keeps only a limited local report history and does not store visitor IP 
addresses, user agents, referrers, or script samples.

### Does Volixta work with Nginx?

Yes.

Nginx does not use `.htaccess`, so Volixta provides ready-to-copy configuration 
for supported HTTPS redirects and Security Headers instead of attempting to modify`.
htaccess`.

### Can I use Volixta locally?

Yes.

Volixta detects common local environments such as `localhost`, `.local`, and `.test`.

A public Let’s Encrypt certificate is not required locally. If you want trusted 
local HTTPS, Volixta provides guidance for tools such as mkcert.

### Does Volixta slow down my website?

Most plugin operations run only in the WordPress admin area.

Certificate issuance, hosting communication, Deep Scan, Database Cleanup, and configuration
operations do not run during normal frontend requests.

Only explicitly enabled frontend features, such as the PHP redirect fallback or 
Live Fixer, add frontend processing.

### Does Volixta collect personal data?

Volixta does not include visitor analytics or usage tracking.

Some features communicate with external services only when required for an operation
you request, such as Let’s Encrypt certificate issuance or a configured hosting-
panel connection.

## نقد و بررسی‌ها

![](https://secure.gravatar.com/avatar/1d2d41e0e02c5fae1a9880637e701dc20c3e85160c5bc74392f0d05cd3cb81df?
s=60&d=retro&r=g)

### 󠀁[Great work in the more recent updates!](https://wordpress.org/support/topic/great-work-in-the-more-recent-updates/)󠁿

 [IFX](https://profiles.wordpress.org/ifx64/) 27 آگوست 2026 1 پاسخ

I had regular issues with earlier versions (prior to 1.1.2), so stopped using it
on most sites, but after updating on the one site I still had it installed on – 
this latest version (currently 1.3.4) is so much better (I hadn’t updated since 
1.1.2 so improvements were probably already there before 1.3.4 😉 ) UI has improved
as well, and haven’t run into any issues – working great so far, so it looks like
I’ll be adding it back to my other sites again 😉 Thanks so much for this really
useful and convenient plugin!

 [ خواندن تمامی 3 نقد و بررسی‌ ](https://wordpress.org/support/plugin/volixta-ssl-security-headers/reviews/)

## توسعه دهندگان و همکاران

“Volixta SSL & Security Headers” نرم افزار متن باز است. افراد زیر در این افزونه 
مشارکت کرده‌اند.

مشارکت کنندگان

 *   [ VOLIXTA TEAM ](https://profiles.wordpress.org/volixta/)

[ترجمه “Volixta SSL & Security Headers” به زبان شما.](https://translate.wordpress.org/projects/wp-plugins/volixta-ssl-security-headers)

### علاقه‌ مند به توسعه هستید؟

[کد را مرور کنید](https://plugins.trac.wordpress.org/browser/volixta-ssl-security-headers/)،
[مخزن SVN](https://plugins.svn.wordpress.org/volixta-ssl-security-headers/) را بررسی
کنید، یا از طریق [RSS](https://plugins.trac.wordpress.org/log/volixta-ssl-security-headers/?limit=100&mode=stop_on_copy&format=rss)
در [گزارش توسعه](https://plugins.trac.wordpress.org/log/volixta-ssl-security-headers/)
مشترک شوید.

## گزارش تغییرات

#### 1.3.4 – 2026-08-23

 * Redesigned the Security Headers workspace with one clear primary action, stronger
   status hierarchy, full-width category navigation, progress indicators, and improved
   responsive behavior.
 * Added plain-language labels and descriptions to advanced header and CSP fields
   while preserving the technical header names.
 * Added unsaved-change feedback and keyboard navigation for Security Headers tabs.
 * Fixed critical-header warnings in the card-based advanced editor.
 * Fixed the active HTTPS redirect row so its Enabled status and Disable button 
   remain aligned on desktop and mobile.

#### 1.3.3 – 2026-08-23

 * Fixed stale admin asset caching that could leave the Security Headers category
   cards unstyled and display oversized SVG icons.
 * Fixed the local Security Headers testing action so it now uses the PHP runtime
   without changing local .htaccess rules.
 * Prevented runtime Security Headers and persistent Secure Cookie rules from remaining
   unexpectedly active after plugin deactivation.
 * Completed the Security Headers reset confirmation message.

#### 1.3.2 – 2026-08-22

 * Updated readme.txt

#### 1.3.1 – 2026-08-22

 * Improved wp-config.php handling and safety.
 * Improved Secure Cookie Protection reliability.
 * Minor security and stability improvements.

#### 1.3.0 – 2026-08-22

 * Added Secure Cookie Protection for WordPress authentication and PHP sessions.
 * Added Secure, HttpOnly, and SameSite=Lax protection for PHP session cookies.
 * Added direct wp-config.php safety download before persistent Secure Cookie changes.
 * Added Secure Cookie checks to WordPress Site Health.
 * Added Content Security Policy enforcement and Report-Only controls.
 * Added CSP Report-Only monitoring with local violation reports.
 * Added privacy-focused CSP report handling with rate limiting and capped report
   storage.
 * Redesigned Security Headers navigation with dedicated Headers and Content Security
   Policy sections.
 * Added Secure Cookies to the SSL & HTTPS tools.
 * Improved .htaccess and wp-config.php safeguards for sensitive configuration changes.
 * Improved Safety Backup handling for configuration changes.
 * Improved uninstall cleanup and configuration-file safety.

#### 1.2.2 – 2026-08-21

 * Updated readme.txt

#### 1.2.1 – 2026-08-21

 * Fixed WordPress compatibility metadata for WordPress 7.1

#### 1.2.0 – 2026-08-21

This is a major update to Volixta SSL & Security Headers.

 * Added native Let’s Encrypt / ACME certificate issuance directly from WordPress.
 * Added hosting-aware SSL installation for cPanel, Plesk, and DirectAdmin.
 * Added automatic renewal for eligible managed certificates.
 * Added certificate validation, active-certificate detection, expiration information,
   and protected SSL file management.
 * Added Let’s Encrypt staging support and rate-limit protection with retry-time
   detection.
 * Added manual certificate download and installation support.
 * Redesigned the Guided Setup for certificate creation, installation, HTTPS activation,
   redirects, recovery, and Security Headers.
 * Added dedicated localhost support with optional local HTTPS and mkcert guidance.
 * Added `.htaccess` Safety Backups and automatic rollback protection.
 * Added managed-block validation, concurrent-change detection, symlink refusal,
   backup verification, and fail-closed `.htaccess` editing.
 * Redesigned Mixed Content tools with manual frontend verification, Deep Scan, 
   Live Fixer only when needed, and serialization-safe Database Cleanup.
 * Expanded Recommended and Advanced Security Header controls.
 * Improved Apache, LiteSpeed, Nginx, reverse-proxy, and hosting compatibility.
 * Improved SSL, certificate, server, and hosting diagnostics.
 * Improved mobile responsiveness and admin UX across the plugin.
 * Improved security checks, escaping, sanitization, SQL handling, and WordPress.
   org compatibility.
 * Fixed multiple edge cases and regression issues discovered during the 1.2.0 development
   audit.

#### 1.1.6 – 2026-08-20

 * Tested up to WordPress 7.1.

#### 1.1.5 – 2026-05-21

 * Tested up to WordPress 7.0.

#### 1.1.4 – 2026-03-11

 * Updated readme.txt.

#### 1.1.3 – 2026-03-09

 * Removed the Security Hardening module to improve stability and compatibility.

#### 1.1.2 – 2025-12-10

 * Added Security Hardening controls for Secure and HttpOnly cookies.
 * Added directory-indexing protection.
 * Added user-enumeration protection.
 * Improved PHPCS compliance and sanitization.
 * Updated the uninstall routine.
 * Improved the Security Hardening interface.
 * Updated readme.txt.

#### 1.1.1

 * Tested up to WordPress 6.9.

#### 1.1.0

 * Improved SSL detection and code compliance.

#### 1.0.10

 * Updated readme.

#### 1.0.0

 * Initial release.

## اطلاعات

 *  نگارش **1.3.4**
 *  آخرین به‌روزرسانی **1 هفته پیش**
 *  نصب‌های فعال **10+**
 *  نگارش وردپرس ** 5.8 یا بالاتر **
 *  آزمایش‌شده تا **7.1**
 *  نگارش PHP ** 7.4 یا بالاتر **
 *  زبان
 * [English (US)](https://wordpress.org/plugins/volixta-ssl-security-headers/)
 * برچسب
 * [https](https://fa.wordpress.org/plugins/tags/https/)[lets encrypt](https://fa.wordpress.org/plugins/tags/lets-encrypt/)
   [mixed content](https://fa.wordpress.org/plugins/tags/mixed-content/)[Security Headers](https://fa.wordpress.org/plugins/tags/security-headers/)
   [ssl](https://fa.wordpress.org/plugins/tags/ssl/)
 *  [نمایش پیشرفته](https://fa.wordpress.org/plugins/volixta-ssl-security-headers/advanced/)

## امتیازها

 5 از 5 ستاره.

 *  [  امتیاز 1 5-ستاره     ](https://wordpress.org/support/plugin/volixta-ssl-security-headers/reviews/?filter=5)
 *  [  امتیاز 0 4-ستاره     ](https://wordpress.org/support/plugin/volixta-ssl-security-headers/reviews/?filter=4)
 *  [  امتیاز 0 3-ستاره     ](https://wordpress.org/support/plugin/volixta-ssl-security-headers/reviews/?filter=3)
 *  [  امتیاز 0 2-ستاره     ](https://wordpress.org/support/plugin/volixta-ssl-security-headers/reviews/?filter=2)
 *  [  امتیاز 0 1-ستاره     ](https://wordpress.org/support/plugin/volixta-ssl-security-headers/reviews/?filter=1)

[بررسی شما](https://wordpress.org/support/plugin/volixta-ssl-security-headers/reviews/#new-post)

[مشاهدهٔ همهٔ بررسی‌ها](https://wordpress.org/support/plugin/volixta-ssl-security-headers/reviews/)

## مشارکت کنندگان

 *   [ VOLIXTA TEAM ](https://profiles.wordpress.org/volixta/)

## پشتیبانی

چیزی برای گفتن دارید؟ نیاز به کمک دارید؟

 [مشاهده انجمن پشتیبانی](https://wordpress.org/support/plugin/volixta-ssl-security-headers/)