PluginSift
PluginsThemesCompare
Directory
  • Plugins
  • Themes
  • Compare Plugins
Plugin Comparisons
  • SEO
  • Security
  • Ecommerce
  • Page Builders
  • Caching
  • Backup
  • Forms
  • Analytics
Resources
  • About
  • Contact
  • llms.txt

© 2026 PluginSift. Data sourced from WordPress.org. · [email protected]

  1. Home
  2. Plugins
  3. Clickjacking
  4. HTTP Security Header
HTTP Security Header icon

HTTP Security Header

Add and manage essential HTTP security headers with ease. Protect your WordPress site from XSS, clickjacking, and other common vulnerabilities.

By MOHIT GOYAL·Clickjacking·Free
5(3 reviews)
·900 active installs·Updated 3 months ago
DownloadCompare

As of April 2026, HTTP Security Header is a WordPress clickjacking plugin with 900 active installations and a 5/5 rating from 3 reviews. It has been downloaded 4.5K+ times in total. Requires WordPress 5.0+ and PHP 7.0+. Available on WordPress.org since 2024. Top alternative: Headers Security Advanced & HSTS WP.

5/53 reviews
900active installs
4.5K+total downloads
2 yearssince 2024

Overview

HTTP Security Header helps protect your WordPress site by adding critical HTTP headers to each response — with no code required. These headers provide additional layers of protection against attacks such as cross-site scripting (XSS), clickjacking, content injection, and resource leaks.

This plugin offers a modern, responsive admin dashboard with validation, fallback safety, and full control over each header’s default or custom value.

🔎 Scan Your Website Security Headers

Before configuring headers, instantly check your website’s current security score using our online header scanner:

👉 Scan Your Website Security Headers

✔ Enter your website URL
✔ Get instant Security Grade (A+ to F)
✔ See which headers are Present or Missing
✔ Get clear, actionable recommendations
✔ Easily fix them usin…

Read full description on WordPress.org

Screenshots

Ratings & Reviews

53 reviews
5 ★
3
4 ★
0
3 ★
0
2 ★
0
1 ★
0

Compatibility

WordPress5.0+ requiredTested up to 6.9.4
PHP7.0+ required

Top Alternatives to HTTP Security Header

Headers Security Advanced & HSTS WP icon
Headers Security Advanced & HSTS WP
4.990K+ installsUpdated 2 weeks ago
ViewCompare
WP Anti-Clickjack icon
WP Anti-Clickjack
54.0K+ installsUpdated 2 months ago
ViewCompare
Do Not Iframe Me icon
Do Not Iframe Me
010 installsUpdated 13 years ago
ViewCompare
iframe Killer icon
iframe Killer
00 installsUpdated 8 years ago
ViewCompare
View all clickjacking plugins →

Frequently Asked Questions

Changelog

3.1

  • NEW: Real-time validation for custom headers with fallback + admin warnings
  • NEW: “Disable All Headers” button in settings UI
  • NEW: Reset-to-default activates only important headers
  • Improved validation logic for Permissions-Policy, CSP, and Expect-CT
  • Refined translations and I18N compliance
View full changelog on WordPress.org

Contributors

MOHIT GOYALMOHIT GOYAL
Plugin Info
Version
3.1
Last Updated
Dec 30, 2025
WP Requires
5.0+
Tested Up To
6.9.4
PHP Requires
7.0+
Active Installs
900
Downloads
4.5K+
Added
Nov 1, 2024
Business
Free

Tags

clickjackingsecurity headerswordpress securityhttp security headercontent security policy

Developer

M
MOHIT GOYAL
2 plugins0.0M+ total installs
View all plugins →

Quick Compare

HTTP Security Header vs Headers Security Advanced & HSTS WP→HTTP Security Header vs WP Anti-Clickjack→HTTP Security Header vs Do Not Iframe Me→

Plugin data sourced from WordPress.org. Analysis and metrics by PluginSift.