These HTTP headers being used production services by popular websites as Facebook, Google+, Twitter, LinkedIn, YouTube, Yahoo, Amazon, Instagram, Pinterest...
After spending over week studying the requirements to have good website online with CSP I found this WP plugin.
The plugin does what it says it does essential for secure website, and many of these are not often implemented.
Thanks to the author, and as well for continued development and support.
Browse the code, check out SVN repository, or subscribe to the development log by RSS...
Content-Security-Policy header.
X-Permitted-Cross-Domain-Policies header.
Added support of Content-Security-Policy header.
Added support of Referrer-Policy header. 1.1.2.
Added support of 'preload directive to HSTS header. 1.1.1.
Read more