BoundaryGuard Headers
by Jay Suthar 5 (0 reviews)

BoundaryGuard Headers

Automatically enforces essential HTTP security headers to protect your site from XSS, clickjacking, and protocol downgrade attacks.

BoundaryGuard Headers ranks #34,972 among WordPress.org plugins with 10+ active installations, is #1,548 of 4,539 in the Security category, a 5/5 rating from 0 reviews, and was last updated Aug 12, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 7 (Current: 7.1.1)
v2.0.0 Current Version v2.0.0
Updated 1 month ago Last Update on 12 Aug, 2026
Refreshed 11 hours ago Last Refreshed on
#1,548 of 4,539 in Security Top 50% by installs
View on WordPress.org
Rank
#34,972
No change
Active Installs
10+
-33.3%
KW Avg Position
28
0.3 better
Downloads
145
+3 today
Support Resolved
0%
No change
Rating
100%
Review 5 out of 5
5 (0 reviews)

Next Milestone 20

Total Progress 40%
10+ 20+
32,786
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 6 more installs to reach 20+

Rank Changes

33,319 36,901 40,483 44,064 47,646 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026
33,319 36,901 40,483 44,064 47,646 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026
Current #34,972
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026
0 10 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

5.0
0 reviews
Overall 100%
5
0 (0%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Frequently Asked Questions

Common questions about BoundaryGuard Headers

No. BoundaryGuard Headers uses PHP headers, which improves compatibility across different hosting environments.
Yes. The plugin includes a CSP Report-Only Mode that allows you to monitor policy violations without blocking any resources.
No. The plugin is lightweight and adds negligible overhead, as headers are sent as part of the normal HTTP response.
It's a 0-100 score (A+ to F) shown on the Dashboard, based on nine weighted checks across all four header groups. Full breakdown of point values is on the in-plugin Documentation page.
It checks your site's actual live response headers, not just this plugin's own settings — so if a header is already being sent by your host, theme, another plugin, or a CDN, you get credit for it and it's labeled "External" so you always know where the protection is really coming from.
It depends on how caching is set up. Headers are sent through PHP on each request, so they apply whenever WordPress actually handles that request. If a full-page cache serves a stored HTML file directly (bypassing PHP entirely) or a CDN edge serves from its own cache, this plugin's headers won't be part of that cached response. Run the Live Header Scan after setting up caching to confirm the headers are still showing up on the live site — if they're missing, you may need your caching layer to pass through origin response headers, or add matching headers at the server/CDN level as a supplement.
Nonce Mode replaces the looser 'unsafe-inline'/'unsafe-eval' allowance on script-src with a unique per-request nonce, which is a meaningfully stronger policy. It only helps your inline <script> tags if they carry that nonce, though — use the BoundaryGuard_Headers::nonce_attr() helper (see the in-plugin Documentation page) to add it to any inline scripts your theme or plugins output. Turn it on after adapting your inline scripts; otherwise, unnonced inline scripts will be blocked once CSP is enforced.
Switch to CSP Report-Only Mode — it logs what the policy would have blocked without actually blocking anything. Check the Violation Log to see exactly which sources are being flagged, add the legitimate ones to the CSP Builder (presets cover common services like Google Analytics, Stripe, YouTube, etc., or add custom domains), then switch back to enforcing mode once the log is clean.
When "Log Violations" is enabled, visitors' browsers report anything your Content Security Policy blocks (or would block, in Report-Only Mode) to a REST endpoint this plugin registers, and that report is stored in your own database — no third-party service is involved. The Violation Log page shows a 14-day trend, your top blocked sources, and a breakdown by directive, with CSV export and a one-click "Clear Log" (with a confirmation prompt) if you want to start fresh.
Only enable HSTS once your site is reliably served over HTTPS with a valid SSL certificate. HSTS tells browsers to refuse plain-HTTP connections to your domain for the duration you set (one year by default) — if your certificate lapses or you need to fall back to HTTP, visitors won't be able to reach the site until the max-age expires or they manually clear HSTS in their browser.

Sign In / Register

You need to sign in or register to use this feature.