Headers Security Advanced & HSTS WP icon

Headers Security Advanced & HSTS WP

by Andrea Ferro

View on WordPress.org
84 Quality Score
Active Installs
22/30

With roughly 90,000 active installs, this is the most widely used plugin in its niche, though far behind general security suites like Wordfence or Sucuri.

Update Freshness
25/25

The plugin was updated within the past period and is tested against WordPress 7.0, which is unusual since most of the ecosystem is still on 6.x, so the maintenance score reflects very recent activity.

User Rating
15/15

A 98 out of 100 rating from 78 users is exceptional and signals high satisfaction among those who have tried it.

Support Health
8/15

Three support threads with zero resolved is a real concern: the volume is low, but the 0 percent resolution rate suggests the developer may not engage actively in the support forum.

WP Compatibility
15/15

Requiring PHP 7.4 and WordPress 4.7 means it will run on virtually any hosting environment in 2026, and the explicit compatibility with WP 7.0 is a strong signal.

Scores higher than 95% of indexed plugins

About

Best all-in-one WordPress security plugin, uses HTTP & HSTS response headers to avoid vulnerabilities: XSS, injection, clickjacking. Force HTTP/HTTPS.

Active Installs 90k+
Rating ★★★★½ 4.9/5
Last Updated 2026-09-04 8:53pm GMT
Requires WordPress 4.7+
Tested Up To 7.0.4
Requires PHP 7.4+
✓ No known vulnerabilities

What It Does

Headers Security Advanced & HSTS WP configures HTTP response headers on your WordPress site to harden it against common web vulnerabilities, including XSS, clickjacking, and content injection attacks. It also lets you enforce HTTPS by redirecting all HTTP traffic and enables HSTS so browsers refuse to downgrade connections. In practice, you flip a few toggles and the plugin writes the appropriate header rules at the server level.

Who It's For

This plugin is best for site owners who understand what a Content-Security-Policy header is and want a single dashboard to set it up without editing .htaccess or nginx configs by hand. It fits small to medium sites, especially those running on shared hosting where you do not control server-level headers. Developers and agencies managing multiple client sites will also appreciate the centralized header management.

Who Should Skip It

If you already configure security headers at the web server or CDN layer (Cloudflare, Nginx, Apache), adding this plugin is redundant and adds a needless PHP dependency. Beginners who do not know what CSP, X-Frame-Options, or Referrer-Policy mean should look for a guided alternative, since misconfigured headers can break a site.

The Bottom Line

This is the strongest all-in-one security headers plugin in the WordPress ecosystem, with an exceptional 98/100 user rating, broad 90,000-install adoption, and a high overall quality score of 84.39/100. The one real flag is the 0 percent support resolution rate, so do not rely on the developer forum if you hit a tricky configuration issue. For most site owners who want solid header hardening without touching server config, this is the right pick.

Tags

clickjacking csp headers headers security hsts