BACK TO DIRECTORY

Security Headers helps site owners manage modern browser security headers from inside WordPress.
Features include:
- Admin settings page under Security Headers
- HSTS controls with preload warning
- Referrer-Policy and X-Frame-Options settings
- Permissions-Policy custom value field
- Minimal enforced CSP with upgrade-insecure-requests, separate from advanced source restrictions
- Content-Security-Policy builder with Report-Only mode
- Discover / Review / Enforce workflow with explicit source approvals and policy verification
- Untrusted source suggestions from page HTML and browser CSP reports
- Saved pre-workflow settings for recovery
- Diagnostics screen showing configured headers
- Test tool to fetch and inspect your live response headers
- Import, export, and reset settings tools
- Cleanup on uninstall
Why security headers important?
When auditing websites, security headers are frequently forgotten.
Although some may argue that website security is unrelated to SEO, it does become so when a site is compromised and search traffic completely disappears.
Everyone who publishes content online should pay special attention to security headers.
Getting hacked is not good. You lose traffic, customers and it’s a pain to resolve all the issues.
But good thing you’re smart and have searched for this plugin :).
Plugin Details
Active Installs
700Total Downloads
6,178Version
1.6.0Requires WP
6.0Requires PHP
7.4Tested Up To
6.9.7Added
2022-09-24Last Updated
2026-09-17 7:59am GMTRatings
5
1
4
0
3
0
2
0
1
1