Configuration Options
Redirects
Force HTTPS
Redirect all HTTP traffic to HTTPS
Force www
Redirect non-www to www
Remove www
Redirect www to non-www
Trailing Slash
Add trailing slash to URLs
Security
Security Headers
X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, HSTS
Block Directory Browsing
Prevent listing directory contents
Block Sensitive Files
Block .env, .git, .htaccess, etc.
Hotlink Protection
Prevent other sites from embedding your images
Performance
Gzip Compression
Compress text, HTML, CSS, JS, XML, JSON
Browser Caching
Set cache expiry headers for static assets
ETags
Disable ETags (use cache headers instead)
Other
Custom Error Pages
404, 403, 500 error pages
CORS Headers
Allow cross-origin requests (Access-Control-Allow-Origin)
PHP Settings
upload_max_filesize, memory_limit, etc.