HTTP Headers
HTTP Headers adds CORS & security HTTP headers to your website.
HTTP Headers ranks #787 among WordPress.org plugins with 50,000+ active installations, is #101 of 4,518 in the Security category, a 4.3/5 rating from 70 reviews, and was last updated Apr 27, 2026. Data from WordPress.org, refreshed twice daily — see methodology.
Next Milestone 60K
Unlock Exact Install Count
See the precise estimated active installs for this plugin, calculated from real-time ranking data.
- Exact install estimates within tiers
- Track install growth over time
- Milestone progress predictions
Rank Changes
Downloads Growth
Upgrade to Pro
Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.
Upgrade NowReviews & Ratings
Support Threads Overview
Security History
Source: WPVulnerability8 known vulnerabilities on record · 3 in the last 24 months · checked 1 week ago
-
UNPATCHED
HTTP Headers [http-headers] <= 1.19.2 (unfixed)
CVE-2026-1379 · No fix released
-
UNPATCHED
HTTP Headers [http-headers] <= 1.19.2 (unfixed)
CVE-2026-4132 · No fix released
-
UNPATCHED
HTTP Headers [http-headers] <= 1.19.2 (unfixed)
CVE-2026-2717 · No fix released
-
HTTP Headers [http-headers] < 1.19.0
CVE-2023-37978 · Fixed in v1.19.0
-
HTTP Headers [http-headers] < 1.19.0
CVE-2023-37978 · Fixed in v1.19.0
-
HTTP Headers [http-headers] < 1.19.0
CVE-2023-37874 · Fixed in v1.19.0
-
HTTP Headers [http-headers] < 1.18.11
CVE-2023-1208 · Fixed in v1.18.11
-
HTTP Headers [http-headers] < 1.18.9
CVE-2023-1207 · Fixed in v1.18.9
Track This Plugin
Get detailed analytics, keyword tracking, and position alerts delivered to your inbox.
Start Tracking FreePlugin Details
- Version
- 1.19.5
- Last Updated
- Apr 27, 2026
- Requires WP
- 3.2+
- Tested Up To
- 6.9
- PHP Version
- 5.3 or higher
- Author
- Dimitar Ivanov
Support & Rating
- Rating
- ★ ★ ★ ★ ☆ 4.3
- Reviews
- 70
- Support Threads
- 1
- Resolved
- 0%
Keywords
Upgrade to Pro
Unlock keyword rankings, search positions, and detailed analytics with a Pro subscription.
Upgrade NowSimilar Plugins
TL;DR
AI summary of the plugin's readmeThis plugin is for website owners and administrators who need to control the HTTP headers their site sends. It lets them add CORS and security-related headers, such as Content-Security-Policy and X-Frame-Options, without editing server configuration files directly.
- Access-Control-Allow-Origin support
- Content-Security-Policy support
- Strict-Transport-Security support
- X-Frame-Options support
- X-XSS-Protection support
- Referrer-Policy support
- Permissions-Policy support
- Cache-Control support
Frequently Asked Questions
Common questions about HTTP Headers