HTTP Security Header
by MOHIT GOYAL 5 (3 reviews)

HTTP Security Header

Add and manage essential HTTP security headers with ease. Protect your WordPress site from XSS, clickjacking, and other common vulnerabilities.

HTTP Security Header ranks #5,617 among WordPress.org plugins with 1,000+ active installations, a 5/5 rating from 3 reviews, and was last updated Dec 30, 2025. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 6.9.7 (Current: 7.1)
v3.1 Current Version v3.1
Updated 8 months ago Last Update on 30 Dec, 2025
Refreshed 7 hours ago Last Refreshed on
Top 10% by installs
View on WordPress.org
Rank
#5,617
-2 this week
Active Installs
1K+
-41.3%
KW Avg Position
18
0.2 better
Downloads
6.4K
+17 today
Support Resolved
0%
No change
Rating
100%
Review 5 out of 5
5 (3 reviews)

Next Milestone 2K

Total Progress 73.8%
1K+ 2K+
525
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 262 more installs to reach 2K+

Rank Changes

5,609 5,621 5,634 5,646 5,658 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026
5,604 5,628 5,653 5,677 5,701 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026
Current #5,617
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 20 30 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026
0 10 20 30 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

5.0
3 reviews
Overall 100%
5
3 (100%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Security History

Source: WPVulnerability

No known vulnerabilities on record for HTTP Security Header. Checked 1 month ago.

Track This Plugin

Get detailed analytics, keyword tracking, and position alerts delivered to your inbox.

Start Tracking Free

Plugin Details

Version
3.1
Last Updated
Dec 30, 2025
Requires WP
5.0+
Tested Up To
6.9.7
PHP Version
7.0 or higher
Author
MOHIT GOYAL

Support & Rating

Rating
★ ★ ★ ★ ★ 5
Reviews
3
Support Threads
0
Resolved
0%

Keywords

Upgrade to Pro

Unlock keyword rankings, search positions, and detailed analytics with a Pro subscription.

Upgrade Now

TL;DR

AI summary of the plugin's readme

This plugin is for WordPress site owners who want to add security-related HTTP headers without writing code. It solves the problem of sites lacking protections against XSS, clickjacking, content injection, and resource leaks by letting admins configure and validate headers from a dashboard.

  • Visual toggles for headers
  • Default or custom header values
  • Secure fallback for misconfigured headers
  • Integrated header validation
  • Nonce-based saving
  • WP Multisite compatible
  • Disable All / Reset actions
  • Compatible with WP Rocket

Frequently Asked Questions

Common questions about HTTP Security Header

No, this plugin applies headers dynamically using send_headers — making it cache-safe, portable, and compatible with all environments.
Yes, you can configure headers per site on a WordPress Multisite network.
The plugin uses fallback logic to prevent breaking the site by reverting to a known safe default. An admin notice will also appear.
Click the “Reset to Defaults” option in the admin panel to revert settings to secure recommended defaults.
Yes. The “Disable All” button allows you to turn off all headers in a single action.
Some headers like Content-Security-Policy or COEP can affect script loading. Test after enabling them, especially with third-party scripts.
Yes, advanced cross-origin headers like COOP, CORP, and COEP are supported.

Sign In / Register

You need to sign in or register to use this feature.