GD Security Headers icon

GD Security Headers

by Milan Petrovic

View on WordPress.org
73 Quality Score
Active Installs
14/30

With only 1,000 active installs, this is a niche tool that has not gained broad traction compared to the major security plugins in the WordPress ecosystem.

Update Freshness
25/25

It was last updated on 2026-05-12, tested with WordPress 7.0, and requires PHP 7.4, which signals very active and forward-looking maintenance.

User Rating
12/15

Eight ratings producing an 80 out of 100 score is a solid average but the small sample size means real-world confidence is limited.

Support Health
8/15

Zero support threads opened and zero resolved is misleadingly high because there simply is not enough support volume to evaluate responsiveness.

WP Compatibility
15/15

Full marks for compatibility: it declares support for WordPress 7.0 and a modern PHP version, matching current standards.

Scores higher than 30% of indexed plugins

About

Configure various security-related HTTP headers, including CSP, XSS, Referrer Policy and more.

Active Installs 1k+
Rating ★★★★ 4/5
Last Updated 2026-05-12 2:57pm GMT
Requires WordPress 5.5+
Tested Up To 7.0.4
Requires PHP 7.4+

Security History

3 known vulnerabilities, all patched
2 High 1 Medium

Most recent: July 8, 2026

View details ▸

Powered by Wordfence Intelligence

What It Does

GD Security Headers lets WordPress site owners configure security-focused HTTP response headers such as Content Security Policy (CSP), X-XSS-Protection, Referrer-Policy, and Permissions-Policy directly from the admin. Instead of editing .htaccess or web server config files, you toggle these policies through a settings screen. Practically, it sits in front of your site and tells browsers how strictly to handle scripts, frames, and outbound link sharing.

Who It's For

This plugin suits developers and technical site owners who already understand HTTP headers and want a focused, lightweight tool rather than a full security suite. It is a good fit for blogs, SaaS platforms, and small business sites that need to pass compliance checks or harden their headers without paying for Sucuri or Defender. Non-technical users who just want one-click hardening will likely find the configuration options intimidating.

Who Should Skip It

If you only want basic SSL redirection, login lockdown, malware scanning, or a firewall, skip this plugin and pick a broader security tool. Anyone running a mission-critical WooCommerce store, healthcare portal, or financial services site should also avoid relying on a 1,000-install plugin with zero public support activity as their sole layer of defence.

The Bottom Line

GD Security Headers is a well-maintained, highly compatible plugin that does one thing competently, but its tiny install base of 1,000 and lack of public support threads make it a risky choice for high-stakes production sites. It is best suited to technical users on smaller projects who want Dev4Press-level reliability without the bloat of a full security suite. For most site owners, a more popular alternative will be the safer bet.

Tags

content security policy csp dev4press permission policy security