WPThumbs
Themes Plugins By purpose By industry Best-of lists Fix it guides
Free Plugin by SimonRWaters v1.1

Security Headers

Plug-in to ease the setting of TLS headers for HSTS and similar

Security Headers

The facts

Rating
5★ from 8
Active installs
3k+
Price
Free
Last updated
26 Feb 2019
Added
Apr 2015
Requires WP
3.8.1
Tested up to
WP 5.1.24
Requires PHP
5.6
Downloads
48,651

Our analysis

AI-assisted

Security Headers is a WordPress plugin designed to help you manage HTTP headers related to security without needing direct access to your server's configuration. It provides controls for several important security features, including HSTS, HPKP, and protections against content sniffing and XSS attacks.

This plugin is suitable for users who need to enhance their site's security, particularly those operating on shared IP addresses or who lack access to .htaccess files. It is aimed at site administrators looking to implement specific security measures to protect their content and users.

Best for: This plugin is best for website administrators looking to enhance security without direct server access.

What it does well

  • Provides controls for important security headers
  • Helps manage security without server access
  • Supports multiple security features like HSTS and XSS protection
  • Free to use and available on WordPress.org
  • Active installation base of 3,000

Where it falls short

  • Last updated in February 2019
  • Limited information on additional features or support
  • Directory score of 52/100 indicates moderate performance

Verdict

Security Headers offers a straightforward solution for managing HTTP security headers, but its age and moderate directory score may be considerations for potential users.

From the developer

SimonRWaters's own description of Security Headers, lightly tidied.

TLS is growing in complexity. Server Name Indication (SNI) now means HTTPS sites may be on shared IP addresses, or otherwise restricted. For these servers it is handy to be able to set desired HTTP headers without access to the web servers configuration or using .htaccess file.

This plug-in exposes controls for:

  • HSTS (Strict-Transport-Security)
  • HPKP (Public-Key-Pins)
  • Disabling content sniffing (X-Content-Type-Options)
  • XSS protection (X-XSS-Protection)
  • Clickjacking mitigation (X-Frame-Options in main site)
  • Expect-CT

HSTS is used to ensure that future connections to a website always use TLS, and disallowing bypass of certificate warnings for the site.

HPKP is used if you don’t want to rely solely on the Certificate Authority trust model for certificate issuance.

Disabling content sniffing is mostly of interest for sites that allow users to upload files of specific types, but that browsers might be silly enough to interpret of some other type, thus allowing unexpected attacks.

XSS protection re-enables XSS protection for the site, if the user has disabled it previously, and sets the “block” option so that attacks are not silently ignored.

Clickjacking protection is usually only relevant when someone is logged in but users requested it, presumably they have rich content outside of WordPress authentication they wish to protect.

Expect-CT is used to ensure Certificate Transparency is configured correctly.

Read the full description on the official page →

Tagged as

Alternatives

Other plugins for securing a site.

Really Simple Security

Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...

Free 3M+ installs 4.9★ (8,862)
Wordfence Security

Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....

Free 5M+ installs 4.7★ (4,983)
Akismet Anti-spam: Spam Protection

The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...

Free 5M+ installs 4.7★ (1,186)
Loginizer

Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.

Free 1M+ installs 4.8★ (1,030)
Safe SVG

Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.

Free 1M+ installs 4.9★ (79)
All-In-One Security

Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...

Free 1M+ installs 4.7★ (1,715)