Wordpress .htaccess modification no effect

I’m running a wordpress site and made some change to .htaccess file adding the below lines and purge Cache but nothing happens.
I have another wordpress site but not on cloudflare add this same code and its works fine.
Kindly please help…

Header set X-Frame-Options "ALLOW-FROM "
Header set X-XSS-Protection “1; mode=block”
Header set Pragma “no-cache”
Header set Cache-Control “no-cache, no-store”
Header set Strict-Transport-Security “max-age=31536000; includeSubDomains; preload” env=HTTPS
Header set Content-Security-Policy “frame-src https:; worker-src http: https:; manifest-src https:; base-uri https:; upgrade-insecure-requests”
Header set Referrer-Policy “strict-origin-when-cross-origin”

May I ask have you got the selected “Respect Existing Headers” option selected?
Therefore, if you are using some Page Rules, kindly set them to “Cache Standard” (not Cache Everything).

Furthermore, if you are making some changes regarding CSS or JS files, depending on the HTTP cache headers, there could be some issues that Cloudflare has the cached file on the Edge network, while the modified isn’t yet being cached for some time.

Some of the Security headers you can control and setup at SSL/TLS tab → Edge Certificates → HTTP Strict Transport Security (HSTS).


Hi fritexvz,

I have followed the same settings as yours “Respect Existing Headers” and set to Cache Standard but still no luck. I still can’t get the website to read the .htaccess. Is that anything else im missing?

After searching for hour i found CloudFlair completely restricting/blocking htaccess code that they don’t allow with their free CloudFlare servic. Is that true?

Cloudflare should have no impact on your .htaccess file. That’s an Apache config file that executes for inbound requests.

It looks like you’re trying to set headers. You may want to try a manual connection to your site to examine the headers it’s sending:
curl -svo /dev/null https://example.com --connect-to ::

Just change the example.com and IP address so it matches your site and server IP address.

1 Like

This topic was automatically closed 15 days after the last reply. New replies are no longer allowed.