Security Headers
TLS is growing in complexity. Server Name Indication (SNI) now means HTTPS sites may be on shared IP addresses, or otherwise restricted. For these servers it is handy to be able to set desired HTTP headers without…
Consider an alternative
Security Headers shows warning signs in 2026 — compare the alternatives below before installing. It runs on 3K+ sites, is rated 5/5 and was last updated 8 years ago, and scores 40/100 on our health check.
- No update in 7 years
- Only tested up to WordPress 5.1 (latest is 7.1)
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where Security Headers stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| hsts | >100 |
| https | >100 |
| nosniff | #29 |
| tls | >100 |
Version adoption
Share of active sites per release.
Rating breakdown
★★★★★★★★★★ 5 from 8 reviews
About Security Headers
From the official readme · v1.1Description
TLS is growing in complexity. Server Name Indication (SNI) now means HTTPS sites may be on shared IP addresses, or otherwise restricted. For these servers it is handy to be able to set desired HTTP headers without access to the web servers configuration or using .htaccess file.
This plug-in exposes controls for:
- HSTS (Strict-Transport-Security)
- HPKP (Public-Key-Pins)
- Disabling content sniffing (X-Content-Type-Options)
- XSS protection (X-XSS-Protection)
- Clickjacking mitigation (X-Frame-Options in main site)
- Expect-CT
HSTS is used to ensure that future connections to a website always use TLS, and disallowing bypass of certificate warnings for the site.
HPKP is used if you don’t want to rely solely on the Certificate Authority trust model for certificate issuance.
Disabling content sniffing is mostly of interest for sites that allow users to upload files of specific types, but that browsers might be silly enough to interpret of some other type, thus allowing unexpected attacks.
XSS protection re-enables XSS protection for the site, if the user has disabled it previously, and sets the “block” option so that attacks are not silently ignored.
Clickjacking protection is usually only relevant when someone is logged in but users requested it, presumably they have rich content outside of WordPress authentication they wish to protect.
Expect-CT is used to ensure Certificate Transparency is configured correctly.
Installation
- Upload “security_headers.php” to the “/wp-content/plugins/” directory.
- Activate the plugin through the “Plugins” menu in WordPress.
Changelog
Fix for recent WordPress save button
1.1
Fix missing close anchor which breaks recent WordPress
1.0
Add support for wp-login.php page
Add support for Expect-CT header
0.9
Removed unnecessary whitespace in HSTS header (thanks Thomas)
Added Referrer-Policy header
Corrected plugins name from “HTTP Headers” to “Security Header” (thanks Jamie)
Removed trailing semi-colon from X-XSS-Protection (it worked but not needed)
0.8
Add headers to admin section of WordPress
Added option to set the X-Frame-Options headers to main site
Added HSTS Preload header (thanks to Jamie)
0.7
Add report-uri
Fix handling of non-numeric blank strings for HPKP max-age
0.6
HPKP support
Check for TLS before emitting HSTS or HPKP headers
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best Security Headers alternatives
All hsts plugins →FAQ
Security Headers: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Sep 26, 2026
Is Security Headers free?
Yes. Security Headers is free to download and use from the official WordPress.org plugin directory.
Is Security Headers safe to use in 2026?
Security Headers shows warning signs in 2026 — compare the alternatives below before installing. It runs on 3K+ sites, is rated 5/5 and was last updated 8 years ago, and scores 40/100 on our health check.
How many websites use Security Headers?
Security Headers is active on 3K+ WordPress websites and has been downloaded 49,008 times since it launched in April 2015. It was downloaded 384 times in the last 30 days.
Does Security Headers work with WordPress 7.1?
Security Headers is officially tested up to WordPress 5.1.26, while the latest release is 7.1.2. It may still work, but try it on a staging site first.
What PHP version does Security Headers need?
Security Headers requires PHP 5.6 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was Security Headers last updated?
The latest version, 1.1, was released on February 26, 2019 (8 years ago).
Who makes Security Headers?
Security Headers is developed and maintained by SimonRWaters.
What are the best alternatives to Security Headers?
The most popular alternatives to Security Headers are Headers Security Advanced &… (90K+ installs), HSTS Ready (3K+ installs) and LH HSTS (600+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card