I’ve updated the WordPress Security headers plugin.
Added support for the Expect-CT header, be careful use ‘max-age=0’ and don’t enforce till you understand what it is for.
Added the headers to the wp-login.php page which was missing them previously.
Please report bugs or place feature requests on the support page.