sandywp / plugins / security-header
HTTP Security Header
Add and manage essential HTTP security headers with ease. Protect your WordPress site from XSS, clickjacking, and other common vulnerabilities.
Ready in seconds.
v3.1 1,000+ installs WP 5.0+ PHP 7.0+

What you get inside
2 screens-
Example of site secured using HTTP Security Header plugin.
-
Example of missing / weak headers before enabling plugin.
About this plugin
HTTP Security Header helps protect your WordPress site by adding critical HTTP headers to each response — with no code required. These headers provide additional layers of protection against attacks such as cross-site scripting (XSS), clickjacking, content injection, and resource leaks.
This plugin offers a modern, responsive admin dashboard with validation, fallback safety, and full control over each header’s default or custom value.
🔎 Scan Your Website Security Headers
Before configuring headers, instantly check your website’s current security score using our online header scanner:
👉 Scan Your Website Security Headers
✔ Enter your website URL
✔ Get instant Security Grade (A+ to F)
✔ See which headers are Present or Missing
✔ Get clear, actionable recommendations
✔ Easily fix them using this plugin
Used by thousands of websites to enhance security and protect user data.
Features Include:
– Visual toggles for enabling/disabling headers
– Option to use default or custom header values
– Secure fallback if a header is misconfigured
– Integrated header validation
– Support for all major browser-supported headers
– Nonce-based saving and admin notices
– WP Multisite compatible
– “Disable All” and “Reset to Important Headers” actions
– Per-header input validation with real-time error fallback
Supported Headers:
* Strict-Transport-Security (HSTS)
* X-Frame-Options
* X-Content-Type-Options
* Referrer-Policy
* Content-Security-Policy
* Permissions-Policy
* X-XSS-Protection
* X-Permitted-Cross-Domain-Policies
* Expect-CT
* Cross-Origin-Opener-Policy (COOP)
* Cross-Origin-Resource-Policy (CORP)
* Cross-Origin-Embedder-Policy (COEP)
Features
- Lightweight and performance-focused
- No front-end impact
- Choose default or custom header values
- Secure validation and auto-fallbacks
- Seamless plugin compatibility (including WP Rocket)
- Fully translation-ready and i18n-compliant
- Nonce-protected admin save actions
- Optional reset-to-default support
- Reset or disable all headers with one click
Questions
- Does this modify the .htaccess file?
No, this plugin applies headers dynamically using
send_headers— making it cache-safe, portable, and compatible with all environments.- Is this plugin multisite compatible?
Yes, you can configure headers per site on a WordPress Multisite network.
- What happens if a custom value is invalid?
The plugin uses fallback logic to prevent breaking the site by reverting to a known safe default. An admin notice will also appear.
- How do I reset the headers?
Click the “Reset to Defaults” option in the admin panel to revert settings to secure recommended defaults.
- Can I disable all headers at once?
Yes. The “Disable All” button allows you to turn off all headers in a single action.
- Will this block any scripts or resources?
Some headers like
Content-Security-PolicyorCOEPcan affect script loading. Test after enabling them, especially with third-party scripts.- Does this support headers like COOP, CORP, and COEP?
Yes, advanced cross-origin headers like COOP, CORP, and COEP are supported.
sandywp / also on the shelf
Try another plugin
Headers Security Advanced & HSTS WP
4.9 · 90K+ installs
Best all-in-one WordPress security plugin, uses HTTP & HSTS response headers to avoid vulnerabilities: XSS, injection,…
5.0 · 4K+ installs
Protect Your WordPress Site From Clickjacking Attacks by Adding the X-Frame-Options Header and Owasp's Legacy Browser Frame…
10+ installs
Do Not Iframe My Wordpress Site
Spin up a real WordPress site in seconds.
Test plugins, build a demo, hand a client a link — then squash it and start again. No local setup, no Docker.