Beschreibung
HTTP Security Header helps protect your WordPress site by adding critical HTTP headers to each response — with no code required. These headers provide additional layers of protection against attacks such as cross-site scripting (XSS), clickjacking, content injection, and resource leaks.
This plugin offers a modern, responsive admin dashboard with validation, fallback safety, and full control over each header’s default or custom value.
🔎 Scan Your Website Security Headers
Before configuring headers, instantly check your website’s current security score using our online header scanner:
👉 Scan Your Website Security Headers
✔ Enter your website URL
✔ Get instant Security Grade (A+ to F)
✔ See which headers are Present or Missing
✔ Get clear, actionable recommendations
✔ Easily fix them using this plugin
Used by thousands of websites to enhance security and protect user data.
Features Include:
– Visual toggles for enabling/disabling headers
– Option to use default or custom header values
– Secure fallback if a header is misconfigured
– Integrated header validation
– Support for all major browser-supported headers
– Nonce-based saving and admin notices
– WP Multisite compatible
– „Disable All“ and „Reset to Important Headers“ actions
– Per-header input validation with real-time error fallback
Supported Headers:
* Strict-Transport-Security (HSTS)
* X-Frame-Options
* X-Content-Type-Options
* Referrer-Policy
* Content-Security-Policy
* Permissions-Policy
* X-XSS-Protection
* X-Permitted-Cross-Domain-Policies
* Expect-CT
* Cross-Origin-Opener-Policy (COOP)
* Cross-Origin-Resource-Policy (CORP)
* Cross-Origin-Embedder-Policy (COEP)
Features
- Lightweight and performance-focused
- No front-end impact
- Choose default or custom header values
- Secure validation and auto-fallbacks
- Seamless plugin compatibility (including WP Rocket)
- Fully translation-ready and i18n-compliant
- Nonce-protected admin save actions
- Optional reset-to-default support
- Reset or disable all headers with one click
Screenshots
Installation
- Upload the plugin folder to
/wp-content/plugins/ - Activate the plugin via WordPress admin
- Navigate to Settings Security Headers to configure
FAQ
-
Does this modify the .htaccess file?
-
No, this plugin applies headers dynamically using
send_headers— making it cache-safe, portable, and compatible with all environments. -
Is this plugin multisite compatible?
-
Yes, you can configure headers per site on a WordPress Multisite network.
-
What happens if a custom value is invalid?
-
The plugin uses fallback logic to prevent breaking the site by reverting to a known safe default. An admin notice will also appear.
-
How do I reset the headers?
-
Click the “Reset to Defaults” option in the admin panel to revert settings to secure recommended defaults.
-
Can I disable all headers at once?
-
Yes. The “Disable All” button allows you to turn off all headers in a single action.
-
Will this block any scripts or resources?
-
Some headers like
Content-Security-PolicyorCOEPcan affect script loading. Test after enabling them, especially with third-party scripts. -
Does this support headers like COOP, CORP, and COEP?
-
Yes, advanced cross-origin headers like COOP, CORP, and COEP are supported.
Rezensionen
Mitwirkende und Entwickler
„HTTP Security Header“ ist Open-Source-Software. Folgende Menschen haben an diesem Plugin mitgewirkt:
MitwirkendeÜbersetze „HTTP Security Header“ in deine Sprache.
Interessiert an der Entwicklung?
Durchstöbere den Code, sieh dir das SVN Repository an oder abonniere das Entwicklungsprotokoll per RSS.
Änderungsprotokoll
3.1
- NEW: Real-time validation for custom headers with fallback + admin warnings
- NEW: „Disable All Headers“ button in settings UI
- NEW: Reset-to-default activates only important headers
- Improved validation logic for
Permissions-Policy,CSP, andExpect-CT - Refined translations and I18N compliance
3.0
- Added support for Cross-Origin-Embedder-Policy (COEP)
- Refactored header application with auto-fallback and validation
- Introduced full nonce protection and security hardening
- Enhanced admin UI with tooltips and mobile-first design
- Introduced reset-to-defaults architecture
- Removed
.htaccessdependency
2.2
- Merged Feature-Policy with Permissions-Policy
- Improved
.htaccesslogic - Enhanced CSP formatting
2.1
- Added COOP and CORP headers
- Improved UI layout and validation
2.0.3 – 2.0.1
- UI improvements and compatibility fixes
2.0
- Major refactor with modular header handling
1.0
- Initial release


