PluginScout

HTTP Headers

by Dimitar Ivanov · WordPress.org page · Website

v1.19.5 Tested up to WP 6.9.7 PHP 5.3+

HTTP Headers has 50,000+ active installs on WordPress.org and 782,515 downloads all time. We have tracked it since September 4, 2026; download trends appear after 30 days of data. The last update was on April 27, 2026, tested up to WordPress 6.9.7.

HTTP Headers at a glance

Active installs
50,000+
Total downloads
782,515
Downloads, last 30 days
available after 30 days of tracking
30-day growth
tracking since September 4, 2026

Is HTTP Headers well maintained?

Support threads resolved
0 of 1
recent threads on the WordPress.org support forum
WordPress compatibility
Behind
tested up to WordPress 6.9.7, not yet with the current 7.1
One-star reviews
7%
5 of 70 reviews on WordPress.org

Features

The feature list from the plugin's own readme on WordPress.org, trimmed to the essentials.

  • Access-Control-Allow-Origin
  • Access-Control-Allow-Credentials
  • Access-Control-Max-Age
  • Access-Control-Allow-Methods
  • Access-Control-Allow-Headers
  • Access-Control-Expose-Headers
  • Content-Security-Policy
  • Content-Security-Policy-Report-Only
  • Cache-Control
  • Clear-Site-Data
  • Content-Encoding
  • Content-Type

HTTP Headers reviews and ratings

70 reviews on WordPress.org, with the most recent ones as their authors posted them.

4.3 out of 5

70 reviews

5★
51
4★
5
3★
4
2★
5
1★
5
  • Make Main and sub-domain site down

    Never use this plugin as the security settings make my main site and all sub-domain sites down and even after uninstallation / removal of everything and start to install a new WP, it doesn't work anymore

    ysc711
  • worked exactly as promised except 2

    worked exactly as promised except 2

    fairshareitservices
  • Easy to use and almost perfect

    Went through a bunch of options of adding security headers to my sites and settled on this plugin. Would be 5 stars if two things get fixed/added. 1st is that it would be great to have a save button at the top also so you don't have to scroll so much to the bottom to save options (especially on CSP screen). And the 2nd would be that the boxes where we are able to input sites etc, sometimes you have to paste numerous websites in that field and it is ridiculously annoying to try to scroll through, see whats already there or copy and paste outside in notepad for example and then paste it back in. Would be great if that field could be expanded or just bigger.

    sunb1
  • Not compatible with Elementor

    When used with Elementor, you can't edit the pages. Had to uninstall, since I don't know what else it will break.

    RipRapRob
  • effective plugin - save the x-content-type

    I am finding this a very effective tool to help clients reach security compliance. There is one glitch I believe, however, is with the x-content-type-options. Once you enable this the only option is "nosniff". And once enabled, there is no way to reset it. And unfortunately i believe this setting is creating errors on my site. I can't even seem to find the line for it in my .htaccess file. Any recommendations?

    swampscrapper
  • an exceptional plugin - needs updating

    I have felt this has been excellent since the first time I used it, and absolutely no issues with it for what it is, except that there are a couple of headers that either need to be 'marked deprecated' or just removed. My immediate spot of these are the, Features header, P3P header and the Expect-CT (which is still around, but Mozilla recommend not using). There may be others. There are a bunch of things that I might suggest as improvements, but this is to move the tool forward a bit. For instance: It would be great if it could display the highlighted state of the current Apache/Nginx code and the status of the security (as per securityheaders.com form) alongside/under it, so you could see the evolution of the security header set up arrangements as you add/remove them. Could be useful to have some in-built documentation on these things (particularly with the P3P header, those little summary items were impossible to figure out without going back and forth, but for other things like cache-control, or accept-expose-headers, some labelling could help). That said, for advanced users anyway, so perhaps less important. Further to that, it might be useful to have an indication of what OWASP, Scott Helme, and Mozilla recommend and/or warnings for ones that are problematic for security or high risk with labels on them. There are a few things that have odd formatting, so it is not obvious how to transpose the information for the reporting one over from how the header is laid out, since there are different ones for this. In this you have the report header that is normally used (as per report-uri site from Scott Helme) but it does not fit there. However, it has a group called 'csp-element' or something similar that might be clearer as to its use elsewhere). There is also the display of custom headers that are all grouped into one thing, and not spread out in a useful way if you want to review them. Odd grouping in a couple of places, so custom headers I might have given its own

    Jonathan Jewell

Details

HTTP Headers adds CORS & security HTTP headers to your website.

The full description, screenshots and every review live on the WordPress.org page.

Tags

  • cors headers
  • csp header
  • custom headers
  • http-headers
  • Security Headers
Version
1.19.5
Last updated
Apr 27, 2026
First published
May 10, 2016
Requires WordPress
3.2
Tested up to
6.9.7
Requires PHP
5.3
Pricing
Free on WordPress.org

HTTP Headers FAQ

What does HTTP Headers do?

According to its WordPress.org readme, HTTP Headers offers Access-Control-Allow-Origin, Access-Control-Allow-Credentials, Access-Control-Max-Age, Access-Control-Allow-Methods and Access-Control-Allow-Headers.

How many active installs does HTTP Headers have?

WordPress.org reports 50,000+ active installs for HTTP Headers as of September 7, 2026.

Is HTTP Headers still maintained?

Yes. The last release was on April 27, 2026 and it is tested up to WordPress 6.9.7.

Does HTTP Headers have good support?

On the WordPress.org forum, 0 of 1 recent support threads for HTTP Headers are marked resolved. That is the developer's free support; a paid version usually comes with its own channel.

Is HTTP Headers free?

HTTP Headers is free to install from WordPress.org. Many plugins also sell a paid version or add-ons.