sandywp / plugins / headers-security-advanced-hsts-wp

Headers Security Advanced & HSTS WP

4.9 out of 5 stars. 4.9 79 reviews

Best all-in-one WordPress security plugin, uses HTTP & HSTS response headers to avoid vulnerabilities: XSS, injection, clickjacking. Force HTTP/HTTPS.

Launch a sandbox with this plugin → No signup.
Ready in seconds.

v5.3.4 90,000+ installs WP 4.7+ PHP 7.4+

your-sandbox.sandywp.com/wp-admin
Headers Security Advanced & HSTS WP running inside a SandyWP sandbox

What you get inside

8 screens
  • Check HTTP Security Headers (AFTER)

  • Check HTTP Security Headers (BEFORE)

  • Check HTTP Strict Transport Security / HSTS (list)

  • Check WebPageTest (AFTER)

  • Check WebPageTest (BEFORE)

  • Setting on single site installation

  • Check HTTP Security Headers - Serpworx (AFTER)

  • Check HTTP Security Headers - Serpworx (BEFORE)

About this plugin

Headers Security Advanced & HSTS WP is Best all-in-one a free plug-in for all WordPress users. Deactivating this plugin will return your site configuration exactly to the state it was in before.

The Headers Security Advanced & HSTS WP project implements HTTP response headers that your site can use to increase the security of your website. The plug-in will automatically set up all Best Practices (you don’t have to think about anything), these HTTP response headers can prevent modern browsers from running into easily predictable vulnerabilities. The Headers Security Advanced & HSTS WP project wants to popularize and increase awareness and usage of these headers for all wordpress users.

This plugin is developed by OpenHeaders by irn3, we care about WordPress security and best practices.

Check out the best features of Headers Security Advanced & HSTS WP:

  • X-XSS-Protection (Deprecated)
  • Pragma (Deprecated)
  • Public-Key-Pins (Deprecated)
  • Expect-CT (Deprecated)
  • Access-Control-Allow-Origin
  • Access-Control-Allow-Methods
  • Access-Control-Allow-Headers
  • X-Content-Security-Policy
  • X-Content-Type-Options
  • X-Frame-Options
  • X-Permitted-Cross-Domain-Policies
  • X-Powered-By
  • Content-Security-Policy
  • Referrer-Policy
  • HTTP Strict Transport Security / HSTS
  • Content-Security-Policy
  • Content-Security-Policy-Report-Only
  • Clear-Site-Data
  • Cross-Origin-Embedder-Policy-Report-Only
  • Cross-Origin-Opener-Policy-Report-Only
  • Cross-Origin-Embedder-Policy
  • Cross-Origin-Opener-Policy
  • Cross-Origin-Resource-Policy
  • Permissions-Policy
  • Strict-dynamic
  • Strict-Transport-Security
  • FLoC (Federated Learning of Cohorts)

Headers Security Advanced & HSTS WP is based on OWASP CSRF to protect your wordpress site. Using OWASP CSRF, once the plugin is installed, it will provide full CSRF mitigation without having to call a method to use nonce on the output. The site will be secure despite having other vulnerable plugins (CSRF).

HTTP security headers are a critical part of your website’s security. After automatic implementation with Headers Security Advanced & HSTS WP, they protect you from the most notorious types of attacks your site might encounter. These headers protect against XSS, code injection, clickjacking, etc.

We have put a lot of effort into making the most important services operational with Content Security Policy (CSP), below are some examples that we have tested and used with Headers Security Advanced & HSTS WP:

  • CSP usage for Google Tag Manager
    world’s most popular tag manager
  • Using CSP for Gravatar
    Avatar service for WordPress and Social sites
  • Using CSP for WordPress Internal Media
    support WordPress media
  • Using CSP for Youtube Embedded Video SDK
    support Youtube embedded frames and JS SDK
  • CSP usage for CookieLaw
    privacy technology to meet regulatory requirements
  • CSP usage for Mailchimp
    support for Mailchimp automation, SDK and modules
  • CSP usage for Google Analytics
    support for basic conversion domains such as: stats.g.doubleclick.net and www.google.com
  • CSP usage for Google Fonts
    you’re not loading it on the page, chances are one of your SDKs is using it
  • Using CSP for Facebook
    support Facebook SDK functionality
  • Using CSP for Stripe
    highly secure online payment system
  • Using CSP for New Relic
    it’s a registration and monitoring utility
  • Using CSP for Linkedin Tags + SDKs
    support Linkedin Insight, Linkedin Ads and SDK
  • Using CSP for OneTrust
    OneTrust support helps companies manage privacy requirements
  • CSP usage for Moat
    Moat support to measurement suite such as: ad verification, brand safety, advertising and coverage
  • CSP usage for jQuery
    support of jQuery – JS library
  • CSP usage for Twitter Widgets & SDKs
    support Connect, Widgets and the Twitter client-side SDK
  • Using CSP for Google Maps
    support Google Maps as The ggpht used by streetview
  • Using CSP for Quantcast Choice
    Quantcast support for privacy such as GDPR and CCPA
  • CSP usage for Twitter Ads & Analytics
    Twitter support for advertising and Analytics
  • Using CSP for Paypal
    PayPal support for online payment system
  • Using CSP for Drift
    Drift and Driftt support
  • CSP usage for Cookiebot
    cookie and tracker support, GDPR/ePrivacy and CCPA compliance
  • CSP usage for Vimeo Embedded Videos SDK
    support frames, JS SDK, Froogaloop integration
  • Using CSP for AppNexus (now Xandr)
    AppNexus support for custom retargeting
  • Using CSP for Mixpanel
    support analytics tool with SDK/JS to collect client-side data
  • Using CSP for Font Awesome
    toolkit support for fonts and icons over CSS and Less
  • Using CSP for Google reCAPTCHA
    reCAPTCHA support for fraud and bot protection
  • CSP usage for Bootstrap CDN
    Bootstrap support for CSS frameworks
  • Using CSP for HubSpot
    Hubspot support with many features, used for monitoring and mkt functionality
  • Using CSP for Hotjar
    Hotjar tracker support for analytics and metrics
  • Using CSP for WP.com
    support for wp.com hosting
  • Using CSP for Akamai mPulse
    support for Akamai mPulse, for origin and perimeter integrations
  • CSP usage for Cloudflare – Rocket-Loader & Mirage
    support for Mirage libraries for performance acceleration
  • Using CSP for Cloudflare – CDN.js
    Cloudflare’s open CDN support with multiple libraries
  • Using CSP for jsDelivr
    support jsDelivr free CDN for Open Source

Headers Security Advanced & HSTS WP is based on the OWASP CSRF standard to protect your wordpress site. Using the OWASP CSRF standard, once the plugin is installed, you can customize CSP rules for full CSRF mitigation. The site will be secure despite having other vulnerable plugins (CSRF).

Integration with Sentry, Report URI, URIports and Datadog
Sentry is a well-known platform for monitoring and tracking errors in applications. By integrating Sentry with our plugin, users can:
* Receive detailed reports on content security policy (CSP) violations.
* Monitor and analyze JavaScript exceptions occurring on their site.
* Benefit from advanced tools for proactive troubleshooting.

Monitoring and Integration with Sentry, Datadog and URI Reports for optimal security.

Free Forever

Every security header, every configuration option, and every protection this plugin offers today will remain completely free. No features will ever be moved behind a paywall. Shield is a separate set of brand-new monitoring tools built on top. The free plugin gets better because Shield exists, not worse.

Even though FLoC is still fairly new and not yet widely supported, as programmers we think that privacy protection elements are important, so we choose to give you the feature of being opt out of FLoC! We’ve created a special “automatic blocking of FLoC” feature, trying to always offer the best tool with privacy protection and cyber security as main targets and focus.

Analyze your site before and after using Headers Security Advanced & HSTS WP security headers are self-configured according to HTTP Security Headers and HTTP Strict Transport Security / HSTS best practices.

This plugin is updated periodically, our limited support is free, we are available for your feedback (bugs, compatibility issues or recommendations for next updates). We are usually fast :-D.

Shield — Advanced Features (Optional)

Every feature this plugin offers today is and will remain completely free, forever. Shield is a separate set of brand-new advanced tools for professionals who need deeper monitoring and automation:

  • Security Advisor — Analyzes your configuration and gives personalized recommendations in plain language
  • CSP Guide — Recommended tools, safe workflow, WordPress-specific CSP snippets, and CSP FAQ
  • Security Score Dashboard — Real-time A+ to F grade with header status for all 10 security headers
  • Email & Webhook Alerts — Get notified via email, Slack, Discord, Microsoft Teams, or custom webhook when something changes
  • CSP Violation Analytics — See which resources browsers are blocking and why
  • Weekly Automated Scans — Automatic security audit with scan history and trend tracking

Nothing existing moves behind a paywall. Revenue from Shield directly funds free updates and maintenance for all 100,000+ users. Learn more at openheaders.org/pro.

Questions

Will this plugin slow down my site?

No. Headers add less than 1KB to each response. The plugin uses WordPress native hooks and adds no database queries at page load for visitors.

Does it work with Nginx or LiteSpeed?

Yes. As of version 5.3.4 the plugin sends every header a single time via PHP, on any server (Apache, LiteSpeed, Nginx, IIS). It no longer writes headers to .htaccess, so there is only one source and duplicate headers cannot occur.

Does it work with caching plugins?

Yes, for normal PHP-served pages. One honest caveat: some page caches (for example WP Super Cache in “Expert”/mod_rewrite mode, or Cache Enabler) serve fully cached pages as static HTML straight from the web server, bypassing PHP entirely. Those specific responses do not receive the plugin’s headers, because as of 5.3.4 the plugin emits headers only through PHP. Pages served through PHP (the default in most caches, including WP Super Cache “Simple” mode, W3 Total Cache, LiteSpeed Cache, WP Rocket) are unaffected. A dedicated option to cover static/rewrite-served responses is planned as an opt-in feature.

Does it work with Cloudflare?

Yes. Cloudflare passes through headers set by WordPress. If you also set the same headers in the Cloudflare dashboard, disable the matching header in the plugin Settings (“Disable individual headers”) to avoid duplicates.

How do I get an A+ grade on SecurityHeaders.com?

Your site needs all 6 scored headers present: Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and Permissions-Policy. The plugin configures all of these automatically.

Can it conflict with other security plugins?

Rarely. If another plugin or your server sets the same header, you may get duplicates. Open Settings and tick the matching box under “Disable individual headers” to stop this plugin emitting that one header.

What is HSTS?

HTTP Strict Transport Security tells browsers to always use HTTPS. Even if someone types http://, the browser upgrades to https:// automatically. Prevents protocol downgrade attacks.

What max-age should I use for HSTS?

Minimum for preload: 31536000 (1 year). Recommended: 63072000 (2 years). Start with 86400 (1 day) to test, then increase.

4.9

79 reviews

  • 5 ★ 73
  • 4 ★ 3
  • 3 ★ 1
  • 2 ★ 2
  • 1 ★ 0

Ratings come from WordPress.org. SandyWP does not collect its own reviews.

sandywp / also on the shelf

Try another plugin

  • WP Anti-Clickjack

    5.0 · 4K+ installs

    Protect Your WordPress Site From Clickjacking Attacks by Adding the X-Frame-Options Header and Owasp's Legacy Browser Frame…

  • HTTP Security Header

    5.0 · 1K+ installs

    Add and manage essential HTTP security headers with ease. Protect your WordPress site from XSS, clickjacking, and other common…

  • Do Not Iframe Me

    10+ installs

    Do Not Iframe My Wordpress Site

Spin up a real WordPress site in seconds.

Test plugins, build a demo, hand a client a link — then squash it and start again. No local setup, no Docker.