Headers Security Advanced & HSTS WP
by πŸ™ Andrea Ferro 4.9 (77 reviews)

Headers Security Advanced & HSTS WP

Best all-in-one WordPress security plugin, uses HTTP & HSTS response headers to avoid vulnerabilities: XSS, injection, clickjacking. Force HTTP/HTTPS.

Compatible with WP 6.9
v5.2.5 Current Version v5.2.5
Updated 2 days ago Last Update on 18 Jan, 2026
Synced 13 hours ago Last Synced on
Rank
#522
β€” No change
Active Installs
90K+
-3.2%
KW Avg Position
1.4
β€” No change
Downloads
1.3M
+251 today
Support Resolved
38%
β€” No change
Rating
98%
Review 4.9 out of 5
4.9 (77 reviews)

Next Milestone 100K

Total Progress 22.2%
90K+ 100K+
35
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 7,778 more installs to reach 100K+

Rank Changes

496 509 523 536 549 13-01-2026 14-01-2026 15-01-2026 16-01-2026 17-01-2026 18-01-2026 19-01-2026 20-01-2026
496 509 523 537 550 05-01-2026 06-01-2026 07-01-2026 08-01-2026 09-01-2026 10-01-2026 11-01-2026 12-01-2026 13-01-2026 14-01-2026 15-01-2026 16-01-2026 17-01-2026 18-01-2026 19-01-2026 20-01-2026
496 510 524 537 551 21-12-2025 22-12-2025 23-12-2025 24-12-2025 25-12-2025 26-12-2025 27-12-2025 28-12-2025 29-12-2025 30-12-2025 31-12-2025 01-01-2026 02-01-2026 03-01-2026 04-01-2026 05-01-2026 06-01-2026 07-01-2026 08-01-2026 09-01-2026 10-01-2026 11-01-2026 12-01-2026 13-01-2026 14-01-2026 15-01-2026 16-01-2026 17-01-2026 18-01-2026 19-01-2026 20-01-2026
496 510 524 537 551 22-10-2025 23-10-2025 24-10-2025 25-10-2025 26-10-2025 27-10-2025 28-10-2025 29-10-2025 30-10-2025 31-10-2025 01-11-2025 02-11-2025 03-11-2025 04-11-2025 05-11-2025 06-11-2025 07-11-2025 08-11-2025 09-11-2025 10-11-2025 11-11-2025 12-11-2025 13-11-2025 14-11-2025 15-11-2025 16-11-2025 17-11-2025 18-11-2025 19-11-2025 20-11-2025 21-11-2025 22-11-2025 23-11-2025 24-11-2025 25-11-2025 26-11-2025 27-11-2025 28-11-2025 29-11-2025 30-11-2025 01-12-2025 02-12-2025 03-12-2025 04-12-2025 05-12-2025 06-12-2025 07-12-2025 08-12-2025 09-12-2025 10-12-2025 11-12-2025 12-12-2025 13-12-2025 14-12-2025 15-12-2025 16-12-2025 17-12-2025 18-12-2025 19-12-2025 20-12-2025 21-12-2025 22-12-2025 23-12-2025 24-12-2025 25-12-2025 26-12-2025 27-12-2025 28-12-2025 29-12-2025 30-12-2025 31-12-2025 01-01-2026 02-01-2026 03-01-2026 04-01-2026 05-01-2026 06-01-2026 07-01-2026 08-01-2026 09-01-2026 10-01-2026 11-01-2026 12-01-2026 13-01-2026 14-01-2026 15-01-2026 16-01-2026 17-01-2026 18-01-2026 19-01-2026 20-01-2026
Current #522
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 5K 10K 15K 20K 25K 13-01-2026 14-01-2026 15-01-2026 16-01-2026 17-01-2026 18-01-2026 19-01-2026 20-01-2026
0 5K 10K 15K 20K 25K 05-01-2026 06-01-2026 07-01-2026 08-01-2026 09-01-2026 10-01-2026 11-01-2026 12-01-2026 13-01-2026 14-01-2026 15-01-2026 16-01-2026 17-01-2026 18-01-2026 19-01-2026 20-01-2026
0 5K 10K 15K 20K 25K 21-12-2025 22-12-2025 23-12-2025 24-12-2025 25-12-2025 26-12-2025 27-12-2025 28-12-2025 29-12-2025 30-12-2025 31-12-2025 01-01-2026 02-01-2026 03-01-2026 04-01-2026 05-01-2026 06-01-2026 07-01-2026 08-01-2026 09-01-2026 10-01-2026 11-01-2026 12-01-2026 13-01-2026 14-01-2026 15-01-2026 16-01-2026 17-01-2026 18-01-2026 19-01-2026 20-01-2026
0 5K 10K 15K 20K 25K 30K 35K 22-10-2025 25-10-2025 28-10-2025 31-10-2025 03-11-2025 06-11-2025 09-11-2025 12-11-2025 15-11-2025 18-11-2025 21-11-2025 24-11-2025 27-11-2025 30-11-2025 03-12-2025 06-12-2025 09-12-2025 12-12-2025 15-12-2025 18-12-2025 21-12-2025 24-12-2025 27-12-2025 30-12-2025 02-01-2026 05-01-2026 08-01-2026 11-01-2026 14-01-2026 17-01-2026 20-01-2026
0 5K 10K 15K 20K 25K 30K 35K 20-01-2025 01-02-2025 13-02-2025 25-02-2025 09-03-2025 21-03-2025 02-04-2025 14-04-2025 26-04-2025 08-05-2025 20-05-2025 01-06-2025 13-06-2025 25-06-2025 07-07-2025 19-07-2025 31-07-2025 12-08-2025 24-08-2025 05-09-2025 17-09-2025 29-09-2025 11-10-2025 23-10-2025 04-11-2025 16-11-2025 28-11-2025 10-12-2025 22-12-2025 03-01-2026 15-01-2026 20-01-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

4.9
77 reviews
Overall 98%
5
72 (94%)
4
3 (4%)
3
1 (1%)
2
1 (1%)
1
0 (0%)

Tracked Keywords

Showing 5 of 5
Keyword Position Change Type Updated
clickjacking 1 β€” Tag 16 hours ago
hsts 1 β€” Tag 16 hours ago
csp 1 β€” Tag 16 hours ago
headers 2 β€” Tag 16 hours ago
headers security 2 β€” Tag 16 hours ago

Unlock Keyword Analytics

Track keyword rankings, search positions, and discover new ranking opportunities with a Pro subscription.

  • Full keyword position tracking
  • Historical ranking data
  • Competitor keyword analysis
Upgrade to Pro

Support Threads Overview

Resolved
Unresolved
8
Total Threads
3
Resolved
5
Unresolved
38%
Resolution Rate

Track This Plugin

Get detailed analytics, keyword tracking, and position alerts delivered to your inbox.

Start Tracking Free

Plugin Details

Version
5.2.5
Last Updated
Jan 18, 2026
Requires WP
4.7+
Tested Up To
6.9
PHP Version
7.4 or higher

Support & Rating

Rating
β˜… β˜… β˜… β˜… β˜… 4.9
Reviews
77
Support Threads
8
Resolved
38%

Keywords

Upgrade to Pro

Unlock keyword rankings, search positions, and detailed analytics with a Pro subscription.

Upgrade Now

Frequently Asked Questions

Common questions about Headers Security Advanced & HSTS WP

Log in to your Sentry dashboard.
Click on the "Projects" menu item.
Select the project you have created.
Click on the gear icon to open project settings.
In the project settings, go to the "SDK SETUP" section.
Click on "Security Headers".
Copy the automatically generated "REPORT URI" URL and paste it into the "CSP Report URI" field in the plugin settings. Example Sentry Report URI (e.g., https://<your_org>.sentry.io/api/<project_id>/security/?sentry_key=<key>).
The plugin will initialize Sentry and send CSP reports to Sentry.
Log in to your Sentry dashboard.
Click on the "User Icon" at the top right of your screen.
Click "Settings".
Add the domains you want to monitor to the "Monitored Domains" section on the settings page.
Click on "Security Headers".
Copy the automatically generated "URIports" URL and paste it into the "CSP Report URI" field in the plugin settings. Example URIports Report URI (e.g., https://account-subdomain.uriports.com/reports).
The plugin will initialize URIports and send CSP reports to URIports.

Manage CSP reporting with URIports
Why did you choose to integrate with Sentry, URIports, Datadog, and Report URI?
I chose Sentry, URIports, Datadog, and Report URI for integration with this plugin because they are highly reputable and functional platforms in the field of security monitoring. Here's a brief overview of each:

Sentry

Sentry is a well-known platform for monitoring and tracking errors and exceptions in applications. It provides comprehensive tools for logging and analyzing JavaScript errors, making it an excellent choice for monitoring Content Security Policy (CSP) violations. By integrating with Sentry, users can benefit from detailed error reports and proactive issue resolution.

Datadog

Datadog is a powerful platform for monitoring infrastructure, applications, and logs. It offers extensive capabilities for tracking security and performance metrics, including CSP violations. The integration with Datadog allows users to gain insights into the health and security of their websites, providing real-time monitoring and alerting features that are essential for maintaining a secure and performant environment.

Report URI

Report URI is a dedicated service for collecting and analyzing security violation reports, including CSP, HPKP, and other security headers. It is designed specifically to handle large volumes of security reports and provide detailed analytics and visualizations. By using Report URI, users can easily monitor and analyze CSP violations, helping them to quickly identify and mitigate potential security threats.

Each of these platforms offers unique strengths and capabilities, making them ideal choices for comprehensive security monitoring and reporting. By integrating with these well-established services, we aim to provide users with reliable and effective tools to enhance the security of their WordPress websites.

URIports

URIports is a well-known platform for monitoring and tracking errors and exceptions in applications. It provides comprehensive tools for logging and analyzing JavaScript errors, making it an excellent choice for monitoring Content Security Policy (CSP) violations. By integrating with URIports, users can benefit from detailed error reports and proactive issue resolution.
Can I view CSP reports directly in Sentry?
Yes, all CSP reports will be sent to Sentry, where you can view and analyze them in the Sentry control panel.
How do you get an A+ grade?
To earn an A+ grade, your site must issue all HTTP response headers that we check. This indicates a high level of commitment to improving the security of your visitors.
What headers are recommended?
Over an HTTP connection we get Content-Security-Policy, X-Content-Type-Options, X-Frame-Options and X-XSS-Protection. Via an HTTPS connection, 2 additional headers are checked for presence which are Strict-Transport-Security and Public-Key-Pins.

Once the plug-in is activated it performs a test (before and after): https://securityheaders.com/

Can the plugin create slowdowns?
No, Headers Security Advanced & HSTS WP is Fast, Secure and does not affect the SEO and speed of your website.
Content Security Policy (CSP) – Best Practices
When writing your CSP directives in the plugin settings, please follow these rules to avoid invalid configurations:

1. Always use single quotes ' for CSP keywords

CSP keywords must always use straight ASCII single quotes:

'self'
'none'
'unsafe-inline'
'unsafe-eval'
'strict-dynamic'

These are required by the CSP specification.

2. Never use double quotes " inside the CSP

Double quotes are used only outside the policy (for example by Apache when setting headers), not inside the CSP syntax.
Using double quotes inside the policy may break the .htaccess configuration.

3. Do not use β€œsmart quotes” or curly quotes (β€˜ ’ β€œ ”)

Smart quotes often appear when copying text from Word, Google Docs, PDFs, email clients, or mobile keyboards. These characters are invalid in CSP and may cause the browser to reject the policy or Apache to return HTTP 500 errors.

The plugin automatically converts smart quotes to standard quotes, but it is recommended to avoid them when writing your policy.
Starting from version 5.2.4, the plugin automatically:
- Normalizes curly quotes to ASCII quotes
- Replaces invalid double quotes inside the CSP
- Prevents malformed CSP syntax from breaking .htaccess
- Falls back to the built-in default CSP if the input is clearly invalid

This ensures that even incorrect CSP input will not cause the site to crash.
What is HSTS (Strict Transport Security)?
It was created as a solution to force the browser to use secure connections when a site is running on HTTPS. It is a security header that is added to the web server and reflected in the response header as Strict-Transport-Security. HSTS is important because it addresses the following anomalies:
Check before and after using Preload HSTS
This step is important to submit your website and/or domain to an approved HSTS list. Google officially compiles this list and it is used by Chrome, Firefox, Opera, Safari, IE11 and Edge. You can forward your site to the official HSTS preload directory. ('https://hstspreload.org/')
how to use HTTP Strict Transport Security (HSTS)
If you want to use Preload HSTS for your site, there are a few requirements before you can activate it.

Have a valid SSL certificate. You can't do any of this anyway without it.
You must redirect all HTTP traffic to HTTPS (recommended via permanent 301 redirects). This means that your site should be HTTPS only.
You need to serve all subdomains in HTTPS as well. If you have subdomains, you will need an SSL certificate.

The HSTS header on your base domain (for example: example.com) is already configured you just need to activate the plug-in.

If you want to check the HSTS status of your site, you can do so here: https://hstspreload.org/
Can I report a bug or request a feature?
You can report bugs or request new features right support@openheaders[dot]org
Disable FLoC, Google's advertising technology
FLoC is a mega tracker that monitors user activity on all sites, stores the information in the browser, and then uses machine learning to place users into cohorts with similar interests. This way, advertisers can target groups of people with similar interests. Plus, according to Google's own testing, FLoC achieves at least 95% more conversions than cookies.
Who is disabling FLoC by Google?
Scott Helme reported that as of May 3, already 967 of the first 1 million domains had disabled FLoC's interest-cohort in their Permissions-Policy header. That list included some big sites like The Guardian and IKEA.
Do you use CloudFlare and the Headers Security Advanced & HSTS WP plugin?
Are you experiencing any anomalies after a plugin update? If yes, please follow these instructions: clear the cache directly to the CloudFlare Client Area

Log in to your Cloudflare dashboard, and select your account and domain.
Select Caching > Configuration.
Under Cache Purge, select Custom Purge. The custom purge window will be displayed.
Under Purge by, select URL.
Enter the appropriate values in the text field using the format shown in the example.
Run through the additional instructions to complete the form.
Review the data entered.
Click Delete.

This will cause the cloudFlare

Sign In / Register

You need to sign in or register to use this feature.