
Abdal Security Headers applies HTTP security headers from one dashboard. The Smart CSP Assistant watches what the site actually loads, then suggests CSP origins for you to review. Nothing is auto-whitelisted.
Smart CSP Assistant:
- Hybrid discovery: WordPress-registered assets, CSP Report-Only, a runtime observer, and an optional deep file scan of plugins and themes
- Timed learning (15 minutes to 24 hours) or manual stop, with optional continuous monitoring
- Optional deep file scan with a cancellable progress bar; learning duration switches to Manual so a timer cannot stop the scan
- Merge selected origins into existing CSP fields without replacing current values
- Marks findings already present in CSP fields as Added
- Dangerous values require explicit confirmation
- Blocking CSP is paused during learning so the site keeps working
Also included:
- XSS, clickjacking, MIME sniffing, HSTS, Referrer-Policy, and Permissions-Policy, each with its own settings card
- Live CSP header preview and a full-size CSP directive editor
- WordPress hardening cards for X-Powered-By, version hiding, login errors, XML-RPC method policies, X-Pingback, and REST API access control
- Security Profiles for Compatibility, Recommended, Hardened, and Manual that update headers and features without changing CSP
- Export and import all plugin settings as a JSON file from the Settings screen
- Top-level Security Headers menu with a Security Control Center dashboard, Security Headers, Content Security Policy, Security Features, and Settings, RTL, and mobile layout
- Standard WordPress dashboard widget for security status, headers, CSP, and recent activity
Security Headers Managed:
- X-Frame-Options
- X-XSS-Protection
- X-Content-Type-Options
- Strict-Transport-Security (HSTS)
- Content-Security-Policy (CSP)
- Referrer-Policy
- Permissions-Policy
- Access-Control-Allow-Origin
Languages
This plugin is available in the following languages:
– English (en_US)
– Persian (fa_IR)
– Spanish (es_ES)
– Japanese (ja)
– German (de_DE)
– French (fr_FR)
– Portuguese – Brazil (pt_BR)
– Russian (ru_RU)
– Italian (it_IT)
– Turkish (tr_TR)
– Chinese Simplified (zh_CN)
– Arabic (ar)
License
This plugin is released under the AGPLv3 or later License.
License details: https://www.gnu.org/licenses/agpl-3.0.html
Screenshots

Security Control Center dashboard with Security Profiles and live status

Smart CSP Assistant

Content Security Policy

securityheaders.com score before and after enabling the plugin

