This plugin enables HSTS header on WordPress
As of April 2026, Simple HSTS Preload is a WordPress hsts plugin with 20 active installations and a 0/5 rating0. It has been downloaded 2.6K+ times in total. Requires WordPress 4.9+ and PHP false+. Available on WordPress.org since 2018. Last updated 6 years ago — may have compatibility concerns. Top alternative: Headers Security Advanced & HSTS WP.
This plugin enables WordPress to send HSTS header to browser
IMPORTANT NOTE: This plugin won’t work if you use any WordPress caching plugin. If this is the case, then update your .htaccess file to specify HSTS header.
HTTP Strict Transport Security (HSTS) is a web security policy mechanism that helps to protect websites against protocol downgrade attacks and cookie hijacking.
It allows web servers to declare that web browsers (or other complying user agents) should interact with it using only secure HTTPS connections, and never via the insecure HTTP protocol
| WordPress | 4.9+ requiredTested up to 5.2.24 |
| PHP | false+ required |
Plugin data sourced from WordPress.org. Analysis and metrics by PluginSift.