WordPress plugin profile

Flex SSL

Force HTTPS, update site URLs, and add security headers. Supports reverse proxies, certificate checks, and lock-out recovery.

Version1.2.0
Active installs50
Rating0.0 / 5
Tested toWP 7.1

About this plugin

Flex SSL is a lightweight WordPress plugin designed to secure your website by enforcing HTTPS across your entire site. Key features include: Force HTTPS: Automatically redirect all HTTP requests to HTTPS. Encoded and non-ASCII permalinks are preserved. Alias hosts fall back to the WordPress home URL. Auto-Update URLs: Change WordPress site and home URLs from HTTP to HTTPS, with a stored backup you can revert. Cloudflare/Proxy Support: Detects HTTPS headers from Cloudflare, Azure, CloudFront, and other reverse proxies to avoid redirect loops. Security Headers: Optionally add HSTS (includeSubDomains is optional), X-Frame-Options, X-Content-Type-Options, and Referrer-Policy. Mixed Content Fixer: Rewrites this site’s HTTP URLs to HTTPS in content, excerpts, attachments, srcset, scripts, and styles. External links are left unchanged. Tools can scan the front page for leftovers. SSL Status: View certificate expiry, issuer, subject names, trust, and hostname match. Optional admin notices and email before expiry. Redirect Options: Choose between 301 (permanent) and 302 (temporary) for GET. Non-GET requests use 307. Logs, Tools, and Site Health: Monitor changes, test HTTPS, and see Flex SSL tests in Tools → Site Health. Recovery: FLEX_SSL_DISABLE in wp-config.php, Tools → Revert URLs, and wp flex-ssl disable / wp flex-ssl revert-urls . On Multisite, settings and URL updates are per site. License Flex SSL is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 2 of the License, or (at your option) any later version. For more details, see https://www.gnu.org/licenses/gpl-2.0.html.