License: GPLv2 or later WordPress plugin to add secure headers to your website.
As of April 2026, WP Secure HTTP Headers is a WordPress security plugin with 40 active installations and a 0/5 rating0. It has been downloaded 1.2K+ times in total. Requires WordPress 4.3+ and PHP false+. Available on WordPress.org since 2019. Last updated 6 years ago — may have compatibility concerns. Top alternative: Wordfence Security – Firewall, Malware….
This WordPress Plugin add secure headers to you WordPress site.
The Following Headers are included:
– Strict-Transport-Security: Enforces SSL if your website is using SSL (which it should be)
– X-Frame-Options: Prevents Clickjacking
– X-XSS-Protection: Prevents XSS attacks
– X-Content-Type-Options: set to ‘nosniff to prevent MIME-type sniffing
– Referrer-Policy: set to ‘no-referrer-when-downgrade’
| WordPress | 4.3+ requiredTested up to 5.2.24 |
| PHP | false+ required |
Release Date – 15 June 2019
* Initial release
Plugin data sourced from WordPress.org. Analysis and metrics by PluginSift.