360 Orbit Header Security Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
Header Security brings your website up to date with current HTTP security headers:
- Strict-Transport-Security (HSTS)
- X-Frame-Options and CSP frame-ancestors (clickjacking protection, even without a full CSP)
- X-Content-Type-Options
- Referrer-Policy
- Permissions-Policy
- Cross-Origin-Opener-Policy / Cross-Origin-Resource-Policy
- Cookie hardening: adds missing Secure and SameSite attributes to all cookies the website sends
Each header can be switched on and off individually, and its values are fully configurable. A quickstart button enables the recommended settings with a single click.
Free vs. Pro
The free version fully covers all of the basic headers listed above for the frontend.
Header Security Pro adds:
- Content Security Policy (CSP), including a report-only mode for a low-risk start.
- Learning mode: collects everything the CSP would block for a configurable period and only switches to enforcing once no finding is left unreviewed.
- A scanner that automatically detects the external services your site needs (scripts, styles, images, fonts, iframes) and presents them for approval, including bulk approve/block.
- Separate header configuration for the backend (wp-admin); WordPress’s own services are allowed automatically.
- Automatic update notifications directly in the WordPress backend.
Screenshots
Status overview (free version) with the quickstart button. The Content Security Policy and the backend configuration are Pro features.
