Headers Security Advanced & HSTS WP
by Andrea Ferro 4.9 (79 reviews)

Headers Security Advanced & HSTS WP

Best all-in-one WordPress security plugin, uses HTTP & HSTS response headers to avoid vulnerabilities: XSS, injection, clickjacking. Force HTTP/HTTPS.

Headers Security Advanced & HSTS WP ranks #474 among WordPress.org plugins with 90,000+ active installations, is #29 of 2,878 in the Discussion & Community category, a 4.9/5 rating from 79 reviews, and was last updated Sep 4, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 7 (Current: 7.1)
v5.3.5 Current Version v5.3.5
Updated 1 week ago Last Update on 04 Sep, 2026
Refreshed 9 hours ago Last Refreshed on
#29 of 2,878 in Discussion & Community Top 1% by installs Downloads -78.1% this week Actively maintained
View on WordPress.org
Rank
#474
-2 this week
Active Installs
90K+
-9.2%
KW Avg Position
1.8
No change
Downloads
1.4M
+1,436 today
Support Resolved
20%
No change
Rating
98%
Review 4.9 out of 5
4.9 (79 reviews)

Next Milestone 100K

Total Progress 76.5%
90K+ 100K+
8
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 2,353 more installs to reach 100K+

Rank Changes

447 460 473 485 498 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
446 459 472 484 497 31-08-2026 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
Current #474
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

500 1K 1.5K 2K 2.5K 3K 3.5K 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
0 5K 10K 15K 20K 25K 30K 31-08-2026 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

4.9
79 reviews
Overall 98%
5
73 (92%)
4
3 (4%)
3
1 (1%)
2
2 (3%)
1
0 (0%)

Support Threads Overview

Resolved
Unresolved
5
Total Threads
1
Resolved
4
Unresolved
20%
Resolution Rate

Security History

Source: WPVulnerability

No known vulnerabilities on record for Headers Security Advanced & HSTS WP. Checked 1 week ago.

TL;DR

AI summary of the plugin's readme

This plugin is for WordPress site owners and administrators who want to manage HTTP security headers without manual configuration. It automatically sets up HTTP response headers and HSTS to help protect against vulnerabilities like XSS, code injection, and clickjacking.

  • Automatic HTTP security header setup
  • HSTS (HTTP Strict Transport Security)
  • Content Security Policy (CSP) configuration
  • OWASP CSRF mitigation
  • FLoC blocking option
  • Sentry, Datadog, Report URI integration
  • CSP presets for third-party services
  • Security header analysis tools

Frequently Asked Questions

Common questions about Headers Security Advanced & HSTS WP

No. Headers add less than 1KB to each response. The plugin uses WordPress native hooks and adds no database queries at page load for visitors.
Yes. On Apache and LiteSpeed the plugin writes the headers to .htaccess so the web server applies them to every response, including cached HTML and static files, and PHP does not emit a duplicate. On Nginx and IIS (which do not read .htaccess) the headers are sent via PHP, so your normal pages are covered; if you run a server-level cache there, add the equivalent rules to the server config (the plugin's Settings page shows the exact snippet).
Yes. On Apache and LiteSpeed the headers are served at the web-server layer (.htaccess), so they are present even on fully cached pages and on static files that never invoke PHP - including caches that serve static HTML through mod_rewrite: W3 Total Cache (including Disk: Enhanced), WP Super Cache (both "Simple" and "Expert"/mod_rewrite modes), Cache Enabler and WP Fastest Cache. On Nginx and IIS those .htaccess rewrite rules are not read, so a server-level cache that serves HTML without PHP needs the equivalent headers added to the server config by your host; pages served through PHP are covered as usual. Note on WP Rocket: it serves its cache through an early advanced-cache.php drop-in that runs before plugins load, so we do not yet claim coverage for its cached responses on any stack - we have modelled this but not verified it on a live WP Rocket site. If you use WP Rocket, check the cached responses with your browser's network tab and, if a header is missing, add the equivalent rule at the server or CDN level.
Yes. Cloudflare passes through headers set by WordPress. If you also set the same headers in the Cloudflare dashboard, open Settings → "Advanced: per-header delivery" and set the matching header to "Off" to avoid duplicates.
Your site needs all 6 scored headers present: Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and Permissions-Policy. The plugin configures all of these automatically.
Rarely. The plugin detects and resolves its own duplicates automatically. If another plugin or your server sets the same header and a duplicate remains, open Settings → "Advanced: per-header delivery" and set that header to "Server only" (keep the server copy, drop the plugin copy) or "Off".
HTTP Strict Transport Security tells browsers to always use HTTPS. Even if someone types http://, the browser upgrades to https:// automatically. Prevents protocol downgrade attacks.
Minimum for preload: 31536000 (1 year). Recommended: 63072000 (2 years). Start with 86400 (1 day) to test, then increase.
Only if your entire domain (including all subdomains) works over HTTPS. Preload is hardcoded in browsers and difficult to undo. Removal takes months. Test thoroughly first.
CSP tells browsers which resources can load on your page. Anything not explicitly allowed is blocked. It is the strongest protection against XSS attacks.

Sign In / Register

You need to sign in or register to use this feature.