Secure HTTP Headers — WordPress Security Plugin
by shasha310 · WordPress.org page · Website
Secure HTTP Headers has 100+ active installs on WordPress.org and 2,830 downloads all time. We have tracked it since September 4, 2026; download trends appear after 30 days of data. The last update was on April 13, 2021, tested up to WordPress 5.7.17.
Secure HTTP Headers at a glance
Is Secure HTTP Headers well maintained?
Features
The feature list from the plugin's own readme on WordPress.org, trimmed to the essentials.
- HTTP Strict Transport Security – helps to protect websites against man-in-the-middle attacks and cookie hijacking
- X-Frame-Options – helps to protect users against ClickJacking attacks
- X-Content-Type-Options – helps to prevent the browser from MIME-sniffing
- Referrer-Policy – helps to control how much referrer information should be included with requests
- Clear-Site-Data – helps to ensure that data is deleted from the browser if the user logs out
- X-Download-Options – helps to control how IE 8 will handle downloaded HTML files
- Access-Control-Allow-Origin – helps to ensure whether the response can be shared with requesting code from the given origin
- Cross-Origin-Embedder-Policy – helps to prevent a document from loading any cross-origin resources that don’t explicitly grant the document permission
- Permissions-Policy – helps to allow and deny the use of browser features in its own frame, and in content within any iframe elements in the document
- Cross-Origin-Opener-Policy – helps to protect websites against a set of cross-origin attacks dubbed XS-Leaks
- Cross-Origin-Resource-Policy – helps to protect websites against speculative side-channel attacks, like Spectre, as well as Cross-Site Script Inclusion attacks
- X-Permitted-Cross-Domain-Policies – helps to control how cross-domain requests from Flash and PDF documents are handled
Secure HTTP Headers reviews and ratings
2 reviews on WordPress.org, with the most recent ones as their authors posted them.
2 reviews
- 5★
-
1
- 4★
-
0
- 3★
-
0
- 2★
-
0
- 1★
-
1
-
Conflict with other Security Plugin
This plugin has not been thoroughly tested. It caused a code 500 error on our Wordpress installation (good thing it was just staging!), making the site and admin panel inaccessible. Please pull this out of the plugin market as this needs to be tested alongside different security plugins as well.
Mike Padua -
Works.
Thank you for developing this plugin. Combined with another plugin, the default configuration is helping to get the 'A' rating I was looking for from the url test.
Curtis
Details
Secure HTTP headers - Essential, and easy.
The full description, screenshots and every review live on the WordPress.org page.
Rankings Secure HTTP Headers competes in
Tags
- cookies
- hardening
- headers
- security
- Version
- 1.0
- Last updated
- Apr 13, 2021
- First published
- Apr 13, 2021
- Requires WordPress
- 5.3
- Tested up to
- 5.7.17
- Requires PHP
- 7.2
- Pricing
- Free on WordPress.org
Secure HTTP Headers FAQ
What does Secure HTTP Headers do?
According to its WordPress.org readme, Secure HTTP Headers offers HTTP Strict Transport Security – helps to protect websites against man-in-the-middle attacks and cookie hijacking, X-Frame-Options – helps to protect users against ClickJacking attacks, X-Content-Type-Options – helps to prevent the browser from MIME-sniffing, Referrer-Policy – helps to control how much referrer information should be included with requests and Clear-Site-Data – helps to ensure that data is deleted from the browser if the user logs out.
How many active installs does Secure HTTP Headers have?
WordPress.org reports 100+ active installs for Secure HTTP Headers as of September 7, 2026.
Is Secure HTTP Headers still maintained?
The last release was on April 13, 2021, more than a year ago. WordPress.org shows a warning on plugins that go this long without an update.
Is Secure HTTP Headers free?
Secure HTTP Headers is free to install from WordPress.org. Many plugins also sell a paid version or add-ons.