HTTP Security Header icon

HTTP Security Header

by MOHIT GOYAL

View on WordPress.org
66 Quality Score
Active Installs
14/30

With only 1,000 active installs, the plugin has a small but real user base that pulls its visibility score above the baseline weight.

Update Freshness
21/25

A last-updated date of 2025-12-30 and testing against WordPress 6.9.4 indicate an actively maintained plugin that is current with the latest core release.

User Rating
9/15

A perfect 100 out of 100 from 3 ratings is encouraging but statistically thin, so the score is treated as weakly confirmed user satisfaction.

Support Health
8/15

With 0 support threads opened and 0 resolved, there is no track record of responsive help, which limits confidence in future troubleshooting.

WP Compatibility
15/15

Compatibility is at 100 percent, matching the broad WordPress 5.0+ and PHP 7.0+ minimums that cover virtually every modern host.

Scores higher than 17% of indexed plugins

About

Add and manage essential HTTP security headers with ease. Protect your WordPress site from XSS, clickjacking, and other common vulnerabilities.

Active Installs 1k+
Rating ★★★★★ 5/5
Last Updated 2025-12-30 5:44pm GMT
Requires WordPress 5.0+
Tested Up To 6.9.7
Requires PHP 7.0+
✓ No known vulnerabilities

What It Does

HTTP Security Header lets WordPress administrators add and tweak key HTTP response headers such as Content-Security-Policy, X-Frame-Options, and Strict-Transport-Security from a settings page. In practice, it sits between your site and the browser, instructing visitors' browsers to block common attacks like cross-site scripting and clickjacking without modifying code.

Who It's For

This plugin suits administrators of small to mid-sized WordPress sites who want a no-code way to harden their site against the most common header-level vulnerabilities. It is a sensible pick for sites that handle any sensitive data, including e-commerce stores, healthcare pages, and SaaS-adjacent properties, that do not already run a full security suite.

Who Should Skip It

Sites already using a broader security plugin like MalCare, SecuPress, or Headers Security Advanced should skip this to avoid duplicate configuration and conflicting header values.

The Bottom Line

HTTP Security Header delivers a focused, well-maintained solution with strong compatibility and fresh testing against WordPress 6.9.4, earning an overall quality score of 69.19 out of 100. The thin rating base and zero support threads mean you should test header output carefully after install and not rely on community help if something breaks. For most sites running only one security addon, it is a reasonable pick; for complex or high-traffic environments, a more proven alternative is the safer choice.

Tags

clickjacking content security policy http security header Security Headers wordpress security