HTTP Headers


HTTP Headers gives your control over the http headers returned by your blog or website.

Headers supported by HTTP Headers includes:

  • Access-Control-Allow-Origin
  • Access-Control-Allow-Credentials
  • Access-Control-Max-Age
  • Access-Control-Allow-Methods
  • Access-Control-Allow-Headers
  • Access-Control-Expose-Headers
  • Age
  • Content-Security-Policy
  • Content-Security-Policy-Report-Only
  • Cache-Control
  • Clear-Site-Data
  • Connection
  • Content-Encoding
  • Content-Type
  • Cross-Origin-Embedder-Policy
  • Cross-Origin-Opener-Policy
  • Cross-Origin-Resource-Policy
  • Expect-CT
  • Expires
  • Feature-Policy
  • NEL
  • Permissions-Policy
  • Pragma
  • ~~Public-Key-Pins~~
  • ~~Public-Key-Pins-Report-Only~~
  • P3P
  • Referrer-Policy
  • Report-To
  • Strict-Transport-Security
  • Timing-Allow-Origin
  • Vary
  • WWW-Authenticate
  • X-Content-Type-Options
  • X-DNS-Prefetch-Control
  • X-Download-Options
  • X-Frame-Options
  • X-Permitted-Cross-Domain-Policies
  • X-Powered-By
  • X-UA-Compatible
  • X-XSS-Protection

The getting started tutorial describes a typical configuration of this plugin.


  • This screenshot shows up the dashboard with categories of the supported headers.
  • This screenshot shows up the headers of a chosen category and their current values.
  • This screenshot shows up the settings page where you can adjust the security headers.
  • This screenshot shows up the response headers returned by the web server.


Upload the HTTP Headers plugin to your blog. Then activate it.

That’s all.


Why to use this plugin?

Nowadays security of your social data at the web is essential. This plugin helps you to improve your website overall security.

Who use these headers?

These HTTP headers are being used in production services by popular websites as Facebook, Google+, Twitter, LinkedIn, YouTube, Yahoo, Amazon, Instagram, Pinterest.


18. November 2020
Thanks you made easy all the http config in my sites. Thankssss !
2. November 2020
With the help of this plugin you can manage security headers easily. Really well done. But you need to know what you are doing and you need to read a lot of documentation about http headers to understand the meaning of every option. With my little knowledge of http headers security i moved from grade F to D in less than 5 minutes. But i think i've done 10% of the work, maybe less. I wish there was a paid service to configure this plugin.
29. Oktober 2020
Every time you save the settings you get a critical error. Sometimes you have to try 2 or 3 times to get it to save. It's easier to collect the various bits of htaccess code you need from other sources and add them manually.
16. Oktober 2020
This plugin worked on one site just great, another it failed. On the failing site, I had https secure connection on the login page, yet when I typed to login, the result was a notice that the page was not secure. I'm giving a 2 although I think it is a plugin or NGINX conflict, perhaps the hide login plugin since the issue was on the login page. I don't know, so I will list 2. I will list the plugins below. I saw that on another comment you wrote this plugin doesn't work with NGINX. I have NGinx helper plugin, so I have NGinx, so maybe that is the issue. I guess then it will not work. If this is still true, then I suggest you put that in big letters on your WP page so people don't download. I don't think I have technical skills to know how to make it work! I followed most of the suggestions suggested for security, choosing nothing else, and only changed the following: ** "Same Origin"- X-Frame-Options **"strict-origin-when-cross-origin"- Referer Policy** ** "✔ Secure ✔ HttpOnly ✔ SameSite"- Cookie Policy** ** "ambient-light-sensor=(), autoplay=(), camera=(), geolocation=(), microphone=()" - Permissions Policy** These are the details on the FAILing site, theme 2017: Plugins 1. Disable Rest API 2. Easy Accordion 3. Easy Accordion Pro 4. Lightweight Grid Columns 5. Limit Login Attempts Reloaded 6. Nginx Helper 7. Optimize Database After Deleting Revisions 8. QSM Reporting and Analysis 9. Remove "Powered by WordPress" 10. Simple CSS 11. WP Offload Media Lite 12. WP Remove Query Strings From Static Resources 13. WPS Hide Login
18. Juli 2020
Really Nice Job. Thank you very much. Now i´m A in the Security Report Summary.
Lies alle 39 Rezensionen

Mitwirkende & Entwickler

„HTTP Headers“ ist Open-Source-Software. Folgende Menschen haben an diesem Plugin mitgewirkt:


„HTTP Headers“ wurde in 1 Sprache übersetzt. Danke an die Übersetzerinnen und Übersetzer für ihre Mitwirkung.

Übersetze „HTTP Headers“ in deine Sprache.

Interessiert an der Entwicklung?

Durchstöbere den Code, sieh dir das SVN Repository an oder abonniere das Entwicklungsprotokoll per RSS.



Release Date – 29th October, 2020

  • Added „allow-downloads“ and „allow-top-navigation-by-user-activation“ to „sandbox“ directive, part of CSP


Release Date – 20th September, 2020

  • Added „Permissions-Policy“ header
  • Fixed „Cookie Security“


Release Date – 26th July, 2020

  • Added „Cross-Origin-Embedder-Policy“ header
  • Added „Cross-Origin-Opener-Policy“ header


Release Date – 23rd July, 2020

  • Fixed JS/CSS versioning


Release Date – 23rd July, 2020

  • Added the „NEL“ header
  • Fixed the „Report-To“ header


Release Date – 18th June, 2020

  • Fixed a PHP Notice at „Expires“ page
  • Fixed comments in .user.ini file


Release Date – 9th May, 2020

  • Fixed the „Access-Control-Allow-Origin“ header


Release Date – 26th January, 2020

  • Added the „Cross-Origin-Resource-Policy“ header
  • Removed the „Public-Key-Pins“ header


Release Date – 25th November, 2019

  • CORS headers updated (added „Vary: Origin“)


Release Date – 15th September, 2019

  • Simple filtering was replaced with Dynamic filtering


Release Date – 1st September, 2019

  • Added the „Content-Type“ header
  • Fixed the „Access-Control-Allow-Credentials“ header
  • Improvement to „Access-Control-Allow-Headers“ header
  • Improvement to „Access-Control-Allow-Methods“ header
  • Improvement to „Access-Control-Expose-Headers“ header
  • Improvement to „Cache-Control“ header
  • Improvement to „Vary“ header


Release Date – 14th July, 2019

  • Added the „always“ condition to Header (unset) directive
  • Fixed the „import“ function
  • Fixed the „Access-Control-Allow-Origin“ header


Release Date – 16th June, 2019

  • Bugfix in „WWW-Authenticate“ header
  • Added support of Apache 2.4


Release Date – 13th June, 2019

  • Bugfix in „Content-Encoding“ header
  • Bugfix in „Vary“ header


Release Date – 8th June, 2019

  • Added Brotli compression


Release Date – 7th June, 2019

  • Added „SameSite“ to Cookie Security
  • Fixed import/export function
  • Code refactoring


Release Date – 5th April, 2019

  • UI improvement for Content-Security-Policy
  • Fix for Access-Control-Allow-Headers
  • Fix for Access-Control-Allow-Origin
  • Fix for Feature-Policy


Release Date – 9th January, 2019

  • Remove direct calls to cURL


Release Date – 5th January, 2019

  • Better handling of activate/deactivate functions


Release Date – 9th December, 2018

  • Added support of „Clear-Site-Data“ header


Release Date – 6th November, 2018

  • Hotfix: parallel work with third-party plugins


Release Date – 30th September, 2018

  • Support of following Server APIs: CGI, FastCGI, PHP-FPM
  • Error handling improvement


Release Date – 8th August, 2018

  • HSTS improvement
  • CORS improvement


Release Date – 31st July, 2018

  • Export feature bug-fixed


Release Date – 18th July, 2018

  • Feature-Policy header update: new features added


Release Date – 17th July, 2018

  • Added support of „Feature-Policy“ header


Release Date – 12th July, 2018

  • CORS bugfix


Release Date – 13th January, 2018

  • In-plugin security improvement


Release Date – 10th January, 2018

  • Bug fix


Release Date – 4th January, 2018

  • Security improvements


Release Date – 27th December, 2017

  • Updated translations


Release Date – 23th December, 2017

  • Added support of „Report-To“ header
  • Added support of translations
  • Added support of Import/Export
  • Updated „Content-Security-Policy“ header (added directives: object-src, frame-src, worker-src, manifest-src, base-uri, report-to)
  • Updated „WWW-Authenticate“ header (support multiple users)
  • Updated „Access-Control“ headers (added list of origins)


Release Date – 31st August, 2017

  • Added support of „Timing-Allow-Origin“ header
  • Added support of „X-Download-Options“ header
  • Added support of „X-DNS-Prefetch-Control“ header
  • Added support of „X-Permitted-Cross-Domain-Policies“ header
  • Added support of Custom headers


Release Date – 18th August, 2017

  • PHP notice bugfixed


Release Date – 15th August, 2017

  • Added support of „Content-Security-Policy-Report-Only“ header
  • Added support of „Public-Key-Pins-Report-Only“ header
  • Added „1; report=“ directive to the „X-XSS-Protection“ header
  • Added „Inspect headers“ tool
  • UI bugfixes


Release Date – 5th August, 2017

  • Added support of „Expect-CT“ header


Release Date – 30th July, 2017

  • Added support of „Age“ header
  • Added support of „Cache-Control“ header
  • Added support of „Connection“ header
  • Added support of „Content-Encoding“ header
  • Added support of „Expires“ header
  • Added support of „Pragma“ header
  • Added support of „Vary“ header
  • Added support of „WWW-Authenticate“ header
  • Added support of „X-Powered-By“ header
  • Added support of „Secure“ and „HttpOnly“ cookies


Release Date – 5th July, 2017

  • Added support of Apache (via htaccess) inclusion method


Release Date – 3rd June, 2017

  • Added support of Content-Security-Policy header
  • Added dashboard


Release Date – 28th April, 2017

  • Added support of Referrer-Policy header


Release Date – 13th February, 2017

  • Added support of ‚preload‘ directive to HSTS header


Release Date – 8th November, 2016

  • Fixed typo in the X-Frame-Options header


Release Date – 20th May, 2016

  • Added support of P3P header


Release Date – 10th May, 2016

  • Initial version