Skip to main content
< All Topics
Print

HTTPS & Transport

WARNING: Enabling this setting creates an HTTPS redirect through a must-use plugin. Verify that the site already has a valid TLS certificate and that all intended front-end and admin URLs work over HTTPS before enabling it.

Description of the control

Use this control to force all front-end and WordPress admin requests to HTTPS. This helps keep cookies, uploads, and authenticated sessions on encrypted transport.

Procedure

  1. Open Posture Management.
  2. Select Transport & Browser Security.
  3. In the HTTPS & Transport card, locate Enforce HTTPS (front-end & admin).
  4. Review the help text that states the setting will Redirect all HTTP requests to HTTPS using a must-use plugin.
  5. Confirm that the /wp-content/mu-plugins/ directory is writable.
  6. Enable Enable redirect.
  7. Select Save Transport & Browser Settings.

Validation

Confirm that visiting an HTTP URL for the site redirects to the HTTPS version. Test both a front-end page and a WordPress admin URL and verify they load over HTTPS after the setting is saved.

Table of Contents