BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
HTTP Security Header icon
Maintained Tested up to 6.9.9 #3 in clickjacking

HTTP Security Header

HTTP Security Header helps protect your WordPress site by adding critical HTTP headers to each response — with no code required. These headers provide additional layers of protection against attacks such as cross-site…

Active installs1K+1K+ tier
Downloads · 30d335▼ -21.5% vs prev. 30d
Rating5/53 reviews
Health score49/100Fair
All-time downloads6.6KSince Nov 2024
Support resolved—No recent threads
RequiresWP 5.0PHP 7.0+
Downloads · 7d93▲ +20.8% week over week
Our verdict

Use with caution

HTTP Security Header works, but test it on a staging site before relying on it in 2026. It runs on 1K+ sites, is rated 5/5 and was last updated 9 months ago, and scores 49/100 on our health check.

  • Very few reviews so far
  • Only tested up to WordPress 6.9 (latest is 7.1)

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

102132Jul 3Aug 16Sep 30
Yesterday15
Daily average (1y)11
Peak day43Jul 31, 2026
Last 12 months3.8K

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where HTTP Security Header stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
clickjacking #8 48 Best clickjacking plugins →
content security policy #26 4,873 Best content security policy plugins →
http security header #10 4,056 Best http security header plugins →
Security Headers #24 5,480 Best Security Headers plugins →
wordpress security #57 10,000 Best wordpress security plugins →

Version adoption

Share of active sites per release.

  • 3.1100.0%

Rating breakdown

★★★★★★★★★★ 5 from 3 reviews

  • 5★100.0%
  • 4★0.00%
  • 3★0.00%
  • 2★0.00%
  • 1★0.00%

About HTTP Security Header

From the official readme · v3.1

Description

HTTP Security Header helps protect your WordPress site by adding critical HTTP headers to each response — with no code required. These headers provide additional layers of protection against attacks such as cross-site scripting (XSS), clickjacking, content injection, and resource leaks.

This plugin offers a modern, responsive admin dashboard with validation, fallback safety, and full control over each header’s default or custom value.

🔎 Scan Your Website Security Headers

Before configuring headers, instantly check your website’s current security score using our online header scanner:

👉 Scan Your Website Security Headers

✔ Enter your website URL
✔ Get instant Security Grade (A+ to F)
✔ See which headers are Present or Missing
✔ Get clear, actionable recommendations
✔ Easily fix them using this plugin

Used by thousands of websites to enhance security and protect user data.

Features Include:
– Visual toggles for enabling/disabling headers
– Option to use default or custom header values
– Secure fallback if a header is misconfigured
– Integrated header validation
– Support for all major browser-supported headers
– Nonce-based saving and admin notices
– WP Multisite compatible
– “Disable All” and “Reset to Important Headers” actions
– Per-header input validation with real-time error fallback

Supported Headers:
* Strict-Transport-Security (HSTS)
* X-Frame-Options
* X-Content-Type-Options
* Referrer-Policy
* Content-Security-Policy
* Permissions-Policy
* X-XSS-Protection
* X-Permitted-Cross-Domain-Policies
* Expect-CT
* Cross-Origin-Opener-Policy (COOP)
* Cross-Origin-Resource-Policy (CORP)
* Cross-Origin-Embedder-Policy (COEP)

Features

  • Lightweight and performance-focused
  • No front-end impact
  • Choose default or custom header values
  • Secure validation and auto-fallbacks
  • Seamless plugin compatibility (including WP Rocket)
  • Fully translation-ready and i18n-compliant
  • Nonce-protected admin save actions
  • Optional reset-to-default support
  • Reset or disable all headers with one click

Installation

  1. Upload the plugin folder to /wp-content/plugins/
  2. Activate the plugin via WordPress admin
  3. Navigate to Settings → Security Headers to configure

Frequently asked questions

Does this modify the .htaccess file?

No, this plugin applies headers dynamically using send_headers — making it cache-safe, portable, and compatible with all environments.

Is this plugin multisite compatible?

Yes, you can configure headers per site on a WordPress Multisite network.

What happens if a custom value is invalid?

The plugin uses fallback logic to prevent breaking the site by reverting to a known safe default. An admin notice will also appear.

How do I reset the headers?

Click the “Reset to Defaults” option in the admin panel to revert settings to secure recommended defaults.

Can I disable all headers at once?

Yes. The “Disable All” button allows you to turn off all headers in a single action.

Will this block any scripts or resources?

Some headers like Content-Security-Policy or COEP can affect script loading. Test after enabling them, especially with third-party scripts.

Does this support headers like COOP, CORP, and COEP?

Yes, advanced cross-origin headers like COOP, CORP, and COEP are supported.

Changelog

Added Disable All, real-time custom header validation, and improved fallback logic. After updating, review any custom values and re-save to ensure compatibility.

3.1

  • NEW: Real-time validation for custom headers with fallback + admin warnings
  • NEW: “Disable All Headers” button in settings UI
  • NEW: Reset-to-default activates only important headers
  • Improved validation logic for Permissions-Policy, CSP, and Expect-CT
  • Refined translations and I18N compliance

3.0

  • Added support for Cross-Origin-Embedder-Policy (COEP)
  • Refactored header application with auto-fallback and validation
  • Introduced full nonce protection and security hardening
  • Enhanced admin UI with tooltips and mobile-first design
  • Introduced reset-to-defaults architecture
  • Removed .htaccess dependency

2.2

  • Merged Feature-Policy with Permissions-Policy
  • Improved .htaccess logic
  • Enhanced CSP formatting

2.1

  • Added COOP and CORP headers
  • Improved UI layout and validation

2.0.3 – 2.0.1

  • UI improvements and compatibility fixes

2.0

  • Major refactor with modular header handling

Full changelog on WordPress.org →

Screenshots

Example of site secured using HTTP Security Header plugin.
Example of site secured using HTTP Security Header plugin.
Example of missing / weak headers before enabling plugin.
Example of missing / weak headers before enabling plugin.

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best HTTP Security Header alternatives

All clickjacking plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Headers Security Advanced & HSTS WP Headers Security Advanced & HSTS WP Best all-in-one WordPress security plugin, uses HTTP & HSTS response headers to avoid… by Andrea Ferro 90K+ ★★★★★★★★★★ 4.9 (79) 4 weeks ago 78
2 WP Anti-Clickjack WP Anti-Clickjack Protect Your WordPress Site From Clickjacking Attacks by Adding the X-Frame-Options Header… by Andy Feliciotti 4K+ ★★★★★★★★★★ 5 (3) 9 months ago 51
4 Do Not Iframe Me Do Not Iframe Me Do Not Iframe My Wordpress Site by Jesse Lee 10+ ★★★★★★★★★★ No reviews 14 years ago 23
5 iframe Killer iframe Killer Restrict your website to open in iframe from external website. by jitengaikwad <10 ★★★★★★★★★★ No reviews 9 years ago 21

FAQ

HTTP Security Header: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 1, 2026

Is HTTP Security Header free?

Yes. HTTP Security Header is free to download and use from the official WordPress.org plugin directory.

Is HTTP Security Header safe to use in 2026?

HTTP Security Header works, but test it on a staging site before relying on it in 2026. It runs on 1K+ sites, is rated 5/5 and was last updated 9 months ago, and scores 49/100 on our health check.

How many websites use HTTP Security Header?

HTTP Security Header is active on 1K+ WordPress websites and has been downloaded 6,600 times since it launched in November 2024. It was downloaded 335 times in the last 30 days.

Does HTTP Security Header work with WordPress 7.1?

HTTP Security Header is officially tested up to WordPress 6.9.9, while the latest release is 7.1.2. It may still work, but try it on a staging site first.

What PHP version does HTTP Security Header need?

HTTP Security Header requires PHP 7.0 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was HTTP Security Header last updated?

The latest version, 3.1, was released on December 30, 2025 (9 months ago).

Who makes HTTP Security Header?

HTTP Security Header is developed and maintained by MOHIT GOYAL.

What are the best alternatives to HTTP Security Header?

The most popular alternatives to HTTP Security Header are Headers Security Advanced &… (90K+ installs), WP Anti-Clickjack (4K+ installs) and Do Not Iframe Me (10+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.