Configure core HTTP security headers for your WordPress site in a few clicks.
As of April 2026, Fix It Easy Security Headers is a WordPress csp plugin with 10 active installations and a 0/5 rating0. It has been downloaded 269 times in total. Requires WordPress 5.8+ and PHP 7.4+. Available on WordPress.org since 2025. Top alternative: Headers Security Advanced & HSTS WP.
WP Fix It Easy Security Headers adds a simple page under Tools → Security Headers where you can toggle common HTTP security headers:
On activation, all headers are enabled by default and you’re redirected to the settings screen.
For convenience, the page and the Plugins screen include a “Check Headers” button that opens SecurityHeaders.com with your site’s URL prefilled (built dynamically from home_url()).
This plugin ships with a permissive default CSP intended to “work everywhere” out of the box (allows most external sources and inline code). For stronger protection, you should harden the directives for your specific site.
| WordPress | 5.8+ requiredTested up to 6.8.5 |
| PHP | 7.4+ required |
Plugin data sourced from WordPress.org. Analysis and metrics by PluginSift.