Nubivio Security Headers, security.txt & NIS2 Compliance for Healthcare

Changelog

2.2.1

  • Listing and documentation refresh: clearer description covering the NIS2, CRA and security.txt features, and two new screenshots of the Compliance tab. No code changes.

2.2.0

  • New Compliance tab: CRA, GDPR and NIS2 scanning plus site health checks
  • Live verification that configured security headers are actually sent
  • security.txt and headers now scored and mapped to CRA / NIS2 / GDPR clauses
  • Compliance score with per-framework breakdown
  • Generators: Vulnerability Disclosure Policy, CycloneDX SBOM, EU/NEN 7510 conformity declaration
  • Printable compliance report (browser print to PDF, no added dependencies)
  • Existing header and security.txt hardening unchanged

2.1.2

  • Added plugin icon, banner and a settings page screenshot for the WordPress.org listing

2.1.1

  • All filesystem reads, writes and deletes now go through the WP_Filesystem API and wp_delete_file()

2.1.0

  • Renamed the plugin to Nubivio Healthcare Security Hardening
  • Admin CSS and JavaScript are now enqueued instead of printed inline
  • The security.txt and PGP key files are now located via get_home_path() so they land at the public site root on subdirectory and custom installs
  • Internal option, cron and nonce keys renamed to the new namespace

2.0.0

  • Settings page for all options
  • internet.nl compliant Content-Security-Policy baseline with Report-Only mode
  • Self-renewing security.txt with CRLF line endings and an expiry kept under one year
  • Hosted PGP public key, linked from security.txt as Encryption
  • Extra security.txt fields: Hiring, CSAF, researcher message and an optional signature
  • Removal of deprecated X-XSS-Protection and Expect-CT headers
  • Gravity Forms email-domain blocking, shown only when Gravity Forms is active

Plugin Website
Visit website

Author
nubivio
Version:
2.2.1
Last Updated
July 2, 2026
Requires
WordPress 5.8
Tested Up To
WordPress 7.0
Requires PHP
7.4

Share Post

Join our newsletter.

Get insights into what’s happening at ChangelogWP right in your inbox. We don’t believe in spam.